CKS Supply Chain Security Practice Question
Which TWO of the following are best practices for securing the software supply chain in a CI/CD pipeline?
⚠ Common exam trap
The CKS exam often tests the misconception that 'latest' tags are safe for CI/CD pipelines, but the trap is that they undermine reproducibility and security, and the exam expects you to recognize that immutable, versioned tags (e.g., SHA256 digests) are the correct practice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scan all container images for known vulnerabilities before deployment
Scanning container images for known vulnerabilities (e.g., using Trivy, Clair, or Grype) before deployment is a fundamental supply chain security practice. It ensures that only images free of critical or high-severity CVEs are promoted to production, reducing the attack surface and preventing exploitation of known flaws.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the 'latest' tag for base images to get the newest features
Why it's wrong here
Using the 'latest' tag makes builds non-reproducible and unverifiable because the tag is a mutable pointer that can be updated at any time, silently introducing new base image versions with unknown changes. This unpredictability can pull in untested dependencies or newly disclosed vulnerabilities, breaking the principle of immutable, auditable artifacts. Always pin images to a specific digest or a versioned tag, and enforce this with admission control.
- ✗
Store sensitive credentials directly in the pipeline YAML file
Why it's wrong here
Committing raw credentials directly into a pipeline YAML file exposes secrets to anyone with repository read access and leaves them in plaintext in version control history, even if later removed. Such secrets often include registry tokens, cloud keys, or database passwords, which are prime targets for exfiltration and are difficult to rotate consistently. Instead, store secrets in a dedicated manager like Kubernetes Secrets with encryption, HashiCorp Vault, or native CI/CD secret stores and reference them via environment variables or mounted files.
- ✓
Scan all container images for known vulnerabilities before deployment
Why this is correct
Scanning every container image for known vulnerabilities before deployment is essential because it maps the image's package and dependency versions against public CVE databases such as NVD and identifies exploitable flaws before they reach runtime. This proactive step lets you choose a patched base image, add remediation layers, or reject the image entirely, thereby minimizing the attack surface. Automated scanners like Trivy, Clair, or Grype inserted into the CI/CD pipeline provide continuous assurance and make security part of the deployment workflow rather than an afterthought.
- ✗
Ignore critical CVEs if they are in development environments
Why it's wrong here
Critical CVEs in development environments are just as dangerous as in production because dev clusters often contain service accounts, source code, or access to internal APIs and can be a pivot point for lateral movement into production. Moreover, images built in dev are frequently promoted unchanged to production, so a compromised dev image carries the vulnerability forward. Attackers intentionally target weaker dev environments to establish persistence, so ignoring critical vulnerabilities there can lead to a full chain of compromise.
- ✓
Sign container images to ensure integrity and authenticity
Why this is correct
Container image signing ensures the image's provenance and integrity by using a cryptographic signature from a trusted publisher, typically via Sigstore/cosign or Docker Content Trust. The signature attaches to a specific image digest, and when verified by a Kubernetes admission controller like Kyverno or OPA, it prevents tampered images or malicious substitutes from being deployed. This gives teams non-repudiation and a clear audit trail, complementing vulnerability scanning by addressing the 'who built it and is it unchanged' question that scanning cannot answer.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.