Courseiva
Supply Chain Security →mediumMultiple Select

CKS Supply Chain Security Practice Question

Which TWO of the following are valid methods to verify the integrity of a container image in a Kubernetes supply chain? (Select 2)

⚠ Common exam trap

The CNCF CKS exam often tests the distinction between integrity verification (e.g., signatures, digests) and other security practices like vulnerability scanning or namespace isolation, leading candidates to mistakenly select scanning or isolation as valid integrity checks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Signing the image with Cosign and verifying the signature before deployment

Cosign is a tool for signing container images using cryptographic keys, and verifying the signature before deployment ensures that the image has not been tampered with since it was signed. This provides integrity and authenticity in the software supply chain, as the signature can be validated against a trusted public key or a keyless identity (e.g., via Fulcio).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Signing the image with Cosign and verifying the signature before deployment

    Why this is correct

    Cosign image signing, backed by Sigstore, creates a cryptographic signature bound to the image digest and the signer's identity (such as an OIDC email). Verifying that signature before deployment confirms both that the image content is unmodified and that it came from an approved publisher, making it a true provenance and tamper-evidence check. Without this step, an attacker who compromises a registry can swap a signed-looking tag for a malicious image and the cluster would have no way to detect the substitution.

  • ✗

    Running the container in a separate namespace

    Why it's wrong here

    A Kubernetes namespace provides logical isolation for resources, RBAC, quotas, and network policies, but it does not inspect or validate the contents of container images. Running a container in a separate namespace does not prevent a compromised or tampered image from executing; it merely limits which cluster resources that container can see or affect. Namespace isolation is a control for blast radius and multi-tenancy, not an integrity or authenticity verification mechanism.

  • ✓

    Using a SHA256 digest instead of a tag in the image reference

    Why this is correct

    Referencing an image by its SHA256 digest pins the deployment to a single, immutable manifest computed from the exact layer contents, so any change to the image produces a different digest and the image pull fails. This prevents tag-mutability attacks where the 'latest' tag is repointed to an unexpected or malicious image, giving you a reproducible and content-addressable image reference. However, a digest alone proves only that content is unchanged; it does not prove who created it, so it is often paired with a signature for full provenance.

  • ✗

    Scanning the image for vulnerabilities using Trivy

    Why it's wrong here

    Trivy and similar vulnerability scanners inspect installed package versions against known CVE databases to find security flaws, but they perform no cryptographic verification of the image's origin or integrity. A maliciously modified image could pass a scan entirely if its payload has no known vulnerabilities, and a legitimate image could fail due to outdated libraries. Scanning is a valuable part of runtime security hygiene, but it is not a substitute for verifying that the image is what an authorized publisher intended to ship.

  • ✗

    Using a base image with the latest tag

    Why it's wrong here

    Using a base image with the 'latest' tag is not a verification technique; 'latest' is a mutable pointer that can be overwritten by the image author or an attacker who compromises the registry, so the same tag may resolve to different image contents over time. This makes deployments non-reproducible and lets a previously validated image silently become an untrusted one without any change to the manifest reference. Image verification requires an immutable reference or a cryptographic signature, and 'latest' actively works against both.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.