Courseiva
Supply Chain Security →mediumMultiple Select

CKS Supply Chain Security Practice Question

Which two of the following are best practices for securing a CI/CD pipeline that builds and deploys container images? (Select TWO.)

⚠ Common exam trap

The CKS exam often tests the distinction between 'best practice' and 'common but insecure shortcut' — candidates may mistakenly think storing secrets as environment variables is acceptable because it works, but the exam expects knowledge of secure alternatives like vault or encrypted CI/CD variables.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scan container images for vulnerabilities in the pipeline

Option A is correct because integrating automated image vulnerability scanning (e.g., Trivy, Clair, or Grype) into the pipeline catches known CVEs in base images and dependencies before the image is pushed or deployed, enabling fail-fast remediation. Option C is correct because signing images after building them (e.g., with Cosign/Notation using Sigstore or Docker Content Trust) establishes provenance and integrity, allowing admission controllers to verify signatures before deployment and preventing tampered or unauthorized images from running. Option B is not a best practice because secrets stored as plaintext environment variables in pipeline configuration can leak through logs, build artifacts, or repository access; a dedicated secrets manager (HashiCorp Vault, AWS Secrets Manager) or OIDC-based short-lived credentials should be used instead. Option D is wrong because running builds as root violates least privilege and increases the blast radius of a compromised build step; rootless builds (e.g., Buildah, Kaniko, or Docker rootless mode) are preferred. Option E is wrong because granting the pipeline service account all permissions violates least privilege and dramatically expands the impact of a supply-chain compromise; scoped, minimal RBAC roles should be assigned per stage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Scan container images for vulnerabilities in the pipeline

    Why this is correct

    Scanning images in the pipeline catches known CVEs in base layers and dependencies before deployment, satisfying the stem's requirement to secure the build stage. This shifts vulnerability detection left, so flawed artefacts never reach the registry or cluster.

  • ✗

    Store secrets as environment variables in the pipeline configuration

    Why it's wrong here

    Environment variables are readable in build logs, process listings and pipeline configuration, exposing credentials to anyone with pipeline or job access. It tempts because variables are convenient and avoid hard-coding, but secrets belong in a dedicated secrets manager injected at runtime, not stored in pipeline configuration.

  • ✓

    Sign container images after building them

    Why this is correct

    Signing images after building them lets Kubernetes admission controllers verify provenance before deployment, satisfying the stem's requirement to secure the build-and-deploy pipeline. Cosign or Notation signatures bind the image digest to a trusted identity, so tampered or substituted images are rejected at admission rather than running in the cluster.

  • ✗

    Run the build process as root to avoid permission issues

    Why it's wrong here

    Running builds as root lets a compromised build step write to the host or container runtime, escalating to node compromise. It tempts because root avoids permission errors during image assembly, but pipelines should run as a non-root user with only the filesystem access the build needs.

  • ✗

    Grant all permissions to the pipeline service account to avoid failures

    Why it's wrong here

    Granting all permissions violates least privilege: a compromised pipeline gains cluster-wide control, enabling lateral movement and image tampering. It tempts because broad rights reduce permission-related build failures, yet the correct approach scopes the service account to only the namespaces and verbs the pipeline genuinely requires.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

Go deeper

Related to this question

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are best practices for securing the software supply chain in a CI/CD pipeline?

medium
  • A.Use the 'latest' tag for base images to get the newest features
  • B.Store sensitive credentials directly in the pipeline YAML file
  • ✓ C.Scan all container images for known vulnerabilities before deployment
  • D.Ignore critical CVEs if they are in development environments
  • ✓ E.Sign container images to ensure integrity and authenticity

Why C: Scanning container images for known vulnerabilities (e.g., using Trivy, Clair, or Grype) before deployment is a fundamental supply chain security practice. It ensures that only images free of critical or high-severity CVEs are promoted to production, reducing the attack surface and preventing exploitation of known flaws.

Variation 2. Which TWO of the following are best practices for securing the container supply chain?

medium
  • ✓ A.Scan images for vulnerabilities in a CI pipeline before deploying.
  • ✓ B.Use image signing and verification (e.g., with cosign) to ensure image integrity.
  • C.Embed API keys directly in container images for authentication.
  • D.Allow all images from any registry without verification to speed up development.
  • E.Use mutable tags like 'latest' for easier updates.

Why A: Scanning images for vulnerabilities in a CI pipeline before deployment is a best practice because it catches known CVEs early, preventing vulnerable images from reaching production. Tools like Trivy, Clair, or Grype integrate into CI/CD to enforce policy gates, ensuring only compliant images proceed.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.