Courseiva
Supply Chain Security →mediumMultiple Select

CKS Supply Chain Security Practice Question

Which TWO of the following are best practices for securing the container supply chain?

⚠ Common exam trap

CNCF often tests the distinction between 'scanning for vulnerabilities' (Option A) and 'signing for integrity' (Option B) as complementary but distinct practices, and the trap is that candidates might think only one is needed or confuse signing with scanning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scan images for vulnerabilities in a CI pipeline before deploying.

Scanning images for vulnerabilities in a CI pipeline before deployment is a best practice because it catches known CVEs early, preventing vulnerable images from reaching production. Tools like Trivy, Clair, or Grype integrate into CI/CD to enforce policy gates, ensuring only compliant images proceed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Scan images for vulnerabilities in a CI pipeline before deploying.

    Why this is correct

    Scanning images for known vulnerabilities in CI, using tools like Trivy or Grype, catches flaws in OS packages and language dependencies before they reach production. Integrate these scans with policy checks that fail the build on critical or high severity CVEs, and also rescan base images on a schedule, since new vulnerabilities are disclosed after the image is built. This is a reactive measure against known issues, distinct from verifying who built the image or that it hasn't been altered.

  • ✓

    Use image signing and verification (e.g., with cosign) to ensure image integrity.

    Why this is correct

    Image signing with cosign cryptographically binds the image manifest to a key held by the publisher, proving identity and origin. Verify the signature in the Kubernetes cluster using an admission controller, such as Kyverno or OPA Gatekeeper, to reject unsigned or tampered images; consider holding keys in a KMS like Vault or AWS KMS. Signing addresses integrity and provenance, whereas vulnerability scanning only identifies known flaws, not whether the artifact is authentic.

  • ✗

    Embed API keys directly in container images for authentication.

    Why it's wrong here

    Baking API keys into container images is dangerous because images are immutable and often shared via registries; any user with pull access can extract secrets by unpacking layers. Secrets also leak from intermediate build layers, so even removing them later in the Dockerfile doesn't remove them from the final image. Instead, mount secrets at runtime via Kubernetes Secrets, a sidecar, or a tool like External Secrets Operator, and rotate them regularly.

  • ✗

    Allow all images from any registry without verification to speed up development.

    Why it's wrong here

    Allowing images from any registry without verification removes a key trust boundary, letting attackers push malicious or vulnerable images that then execute with the service account's privileges. Without an allowlist, admission control, and signature verification, you cannot establish provenance or know who built the artifact and from what source. This practice increases the attack surface from a single compromised or malicious registry to the entire internet, and undermines any supply chain security investments.

  • ✗

    Use mutable tags like 'latest' for easier updates.

    Why it's wrong here

    Using mutable tags like 'latest' means a tag can be overwritten, making it impossible to audit or rollback to the exact code that ran historically, because the tag no longer points to the same digest. An attacker can also overwrite a mutable tag to point to a compromised image, and the cluster would pull it on the next restart. Reproducible deployments require immutable tags derived from commit SHAs or explicit image digests (sha256:...), and you should refer to the digest for immutable deployments.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.