Courseiva
Supply Chain Security →mediumMultiple Select

CKS Supply Chain Security Practice Question

Which TWO of the following are valid methods to supply a Kubernetes manifest to kubesec for static analysis?

⚠ Common exam trap

Kubernetes often tests the distinction between static analysis tools that operate on manifest files versus cluster state commands, leading candidates to mistakenly think `kubectl get` output is equivalent to a raw manifest for scanning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

cat deploy.yaml | kubesec scan /dev/stdin

Option A is correct because kubesec scan accepts a manifest from standard input, and piping the file content via cat deploy.yaml | kubesec scan /dev/stdin explicitly supplies the manifest through /dev/stdin, which kubesec reads as the scan target. Option D is correct because kubesec scan deploy.yaml passes the manifest file path directly as an argument, which is the standard documented way to scan a local YAML file. Option B is not valid because kubectl apply -f deploy.yaml sends the manifest to the Kubernetes API server and outputs the server's apply result, not the original manifest, so kubesec would receive non-manifest text. Option C is not valid because kubectl get deployment myapp -o yaml returns a live Deployment object with runtime metadata and status fields, not a clean input manifest, and kubesec expects a manifest to analyze. Option E is not valid because kubesec has no curl subcommand; it cannot fetch a remote URL in that manner.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    cat deploy.yaml | kubesec scan /dev/stdin

    Why this is correct

    Piping the manifest via cat to kubesec scan with /dev/stdin works because kubesec accepts a file path argument, and /dev/stdin is a valid readable path on Linux. This satisfies the requirement to supply the manifest through standard input rather than a named file.

  • ✗

    kubectl apply -f deploy.yaml | kubesec scan

    Why it's wrong here

    Incorrect. `kubectl apply -f deploy.yaml` deploys the manifest and does not output anything to scan; it is not a valid method for static analysis.

  • ✗

    kubectl get deployment myapp -o yaml | kubesec scan

    Why it's wrong here

    Incorrect. While `kubectl get deployment myapp -o yaml` outputs the YAML, the output includes cluster-specific metadata and status, not the raw manifest. kubesec is designed for static analysis of raw manifest files, not live object output.

  • ✓

    kubesec scan deploy.yaml

    Why this is correct

    kubesec scan accepts a local file path as its argument, reading and parsing the manifest directly. This satisfies the requirement to supply a manifest file without piping or redirection, making it a valid method for static analysis.

  • ✗

    kubesec curl https://example.com/deploy.yaml

    Why it's wrong here

    Incorrect. `kubesec curl` is not a valid command; kubesec does not support fetching manifests from URLs via curl.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.