CKS Supply Chain Security Practice Question
Which TWO of the following are valid methods to supply a Kubernetes manifest to kubesec for static analysis?
⚠ Common exam trap
Kubernetes often tests the distinction between static analysis tools that operate on manifest files versus cluster state commands, leading candidates to mistakenly think `kubectl get` output is equivalent to a raw manifest for scanning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cat deploy.yaml | kubesec scan /dev/stdin
Option A is correct because kubesec scan accepts a manifest from standard input, and piping the file content via cat deploy.yaml | kubesec scan /dev/stdin explicitly supplies the manifest through /dev/stdin, which kubesec reads as the scan target. Option D is correct because kubesec scan deploy.yaml passes the manifest file path directly as an argument, which is the standard documented way to scan a local YAML file. Option B is not valid because kubectl apply -f deploy.yaml sends the manifest to the Kubernetes API server and outputs the server's apply result, not the original manifest, so kubesec would receive non-manifest text. Option C is not valid because kubectl get deployment myapp -o yaml returns a live Deployment object with runtime metadata and status fields, not a clean input manifest, and kubesec expects a manifest to analyze. Option E is not valid because kubesec has no curl subcommand; it cannot fetch a remote URL in that manner.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
cat deploy.yaml | kubesec scan /dev/stdin
Why this is correct
Piping the manifest via cat to kubesec scan with /dev/stdin works because kubesec accepts a file path argument, and /dev/stdin is a valid readable path on Linux. This satisfies the requirement to supply the manifest through standard input rather than a named file.
- ✗
kubectl apply -f deploy.yaml | kubesec scan
Why it's wrong here
Incorrect. `kubectl apply -f deploy.yaml` deploys the manifest and does not output anything to scan; it is not a valid method for static analysis.
- ✗
kubectl get deployment myapp -o yaml | kubesec scan
Why it's wrong here
Incorrect. While `kubectl get deployment myapp -o yaml` outputs the YAML, the output includes cluster-specific metadata and status, not the raw manifest. kubesec is designed for static analysis of raw manifest files, not live object output.
- ✓
kubesec scan deploy.yaml
Why this is correct
kubesec scan accepts a local file path as its argument, reading and parsing the manifest directly. This satisfies the requirement to supply a manifest file without piping or redirection, making it a valid method for static analysis.
- ✗
kubesec curl https://example.com/deploy.yaml
Why it's wrong here
Incorrect. `kubesec curl` is not a valid command; kubesec does not support fetching manifests from URLs via curl.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.