CKS Supply Chain Security Practice Question
Which TWO of the following are valid methods to verify the integrity of a container image? (Select 2)
⚠ Common exam trap
Candidates often confuse vulnerability scanning tools (which find known vulnerabilities) with integrity verification methods (which detect tampering). Trivy is a vulnerability scanner, not an integrity verification tool.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compare the image SHA digest with a known good digest
Container images are identified by a content-addressable digest (SHA256 hash) that uniquely represents the image manifest. Verifying that the SHA digest of a pulled image matches a known good digest from a trusted source ensures the image has not been tampered with or altered in transit, as any change to the image layers or configuration would result in a different digest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use trivy image to check for vulnerabilities
Why it's wrong here
Trivy is a vulnerability scanner that analyzes installed packages and dependencies for known CVEs (e.g., via vulnerability databases) and misconfigurations. It does not, however, provide any cryptographic guarantee of image integrity — it never verifies a digest or signature, so a tampered image with no known vulnerabilities would pass a Trivy scan undetected. Thus, scanning for vulnerabilities is a security best practice but not a valid method for integrity verification.
- ✓
Compare the image SHA digest with a known good digest
Why this is correct
Comparing the image SHA digest against a known-good digest is a direct integrity check because the digest is a cryptographic hash of the image manifest and content. If the computed digest matches the trusted reference, the image is byte-for-byte identical to the verified original; any modification would produce a different digest. This is considered a reliable and tamper-evident method, provided the known-good digest comes from a trusted source and is transmitted over a secure channel.
- ✓
Use cosign verify to check the image signature
Why this is correct
cosign verify is a valid method because it uses Sigstore to verify the image's cryptographic signature against a trusted public key or keyless identity, confirming both authenticity and integrity. A valid signature means the image was signed by a trusted signer and has not been altered since signing — Cosign also confirms that the digest recorded in the signature matches the image being verified. This approach provides strong, attestable proof of integrity and is widely used in Kubernetes supply-chain security.
- ✗
Use docker history to view layers
Why it's wrong here
docker history displays the build-time command history and layer metadata for an image, including the commands run in each step and the layer sizes. This output is informational; it does not generate or compare any cryptographic checksums, and it can even be influenced by build context or history annotations. Therefore, it cannot detect modification of image content and is not a valid integrity verification method.
- ✗
Use kubectl describe pod to check image details
Why it's wrong here
kubectl describe pod retrieves the pod's specification from the Kubernetes API and shows the image reference (e.g., name:tag) that was requested, but it does not inspect the actual container image content fetched from a registry. The command never verifies the image digest, signature, or authenticity — it merely reflects the image string in the pod spec. Consequently, it cannot catch tag mutability, registry compromise, or anything related to the image's actual bytes.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.