Courseiva
Supply Chain Security →easyMultiple Select

CKS Supply Chain Security Practice Question

Which TWO of the following are tools that can be used to generate an SBOM for a container image?

⚠ Common exam trap

The CKS exam often tests the distinction between tools that generate SBOMs (like Syft and Trivy) versus tools that consume, sign, or attach SBOMs (like Cosign), causing candidates to confuse signing capabilities with SBOM generation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Trivy

Trivy is a comprehensive vulnerability scanner that can also generate Software Bill of Materials (SBOM) for container images. It supports multiple output formats such as CycloneDX and SPDX, making it a valid tool for SBOM generation. Syft is specifically designed to generate SBOMs from container images and filesystems, producing output in formats like CycloneDX, SPDX, and Syft's own JSON format. Both tools are widely used in supply chain security workflows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Trivy

    Why this is correct

    Trivy is a versatile security scanner that can also generate SBOMs through its built-in subcommands such as `trivy image --format cyclonedx` and `trivy fs --format spdx`. It enumerates installed packages and libraries from image layers and filesystems using multiple package managers and language ecosystems, then serializes the discovered components into an SBOM document. While Trivy is commonly known for vulnerability scanning, its ability to produce SBOMs in standard formats makes it a correct answer for this question.

  • ✗

    Cosign

    Why it's wrong here

    Cosign is a supply-chain security tool from the sigstore project used to sign container images and verify those signatures, as well as to manage attestations and keyless signing. It does not inspect container layers or filesystems and has no functionality to discover installed packages or dependency manifests, so it cannot generate an SBOM. You could use Cosign to sign an externally produced SBOM file or attach it as an in-toto attestation, but the SBOM itself must come from a different tool.

  • ✓

    Syft

    Why this is correct

    Syft is a purpose-built SBOM generator from Anchore that creates component inventories from container images and filesystem directories. It uses static analysis to inspect installed OS packages, language-specific dependency manifests, and binary metadata, then emits standards-compliant SBOM documents in SPDX and CycloneDX formats. Because Syft is designed specifically for SBOM creation and can run as a CLI or library without executing the image, it directly satisfies the requirement to generate an SBOM.

  • ✗

    Clair

    Why it's wrong here

    Clair is an open-source vulnerability scanner that performs static analysis on container image layers and compares the installed package versions against known CVE databases. Although it parses package metadata to identify affected components, its only output is a list of vulnerabilities and severity ratings, not a neutral software-bill-of-materials document. Thus, Clair is a downstream consumer of SBOM-like data, not a generator of SBOMs in formats such as SPDX or CycloneDX.

  • ✗

    Kubesec

    Why it's wrong here

    Kubesec evaluates Kubernetes manifests and YAML configurations to produce a security risk score and a list of remediation recommendations based on pod security contexts, resource limits, and other declarative settings. It never reads container image contents and has no dependency discovery or package enumeration capabilities, so it cannot produce an SBOM. Kubesec is a static analysis linter for cluster resource definitions, placing it outside the software-supply-chain tooling category this question targets.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security team wants to generate an SBOM for a container image. Which tool should they use?

hard
  • A.Clair
  • B.Trivy
  • C.Cosign
  • ✓ D.Syft

Why D: Syft is a CLI tool specifically designed to generate a Software Bill of Materials (SBOM) from container images and filesystems. It can output SBOMs in multiple formats, including CycloneDX and SPDX, which are the industry-standard formats for SBOMs. This makes Syft the correct choice for the security team's requirement.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.