Courseiva
Supply Chain Security →mediumMultiple Select

CKS Supply Chain Security Practice Question

Which TWO of the following are valid methods to verify the integrity of a container image before deployment?

⚠ Common exam trap

The CNCF exam often tests the distinction between integrity verification (cryptographic guarantees) and security scanning or metadata generation, leading candidates to confuse vulnerability scanning or SBOM generation with integrity checks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the image digest (SHA256) instead of a tag

Using the image digest (SHA256) provides a cryptographic hash of the image manifest, ensuring that the exact same image content is pulled every time, regardless of tag changes. This prevents tag mutability attacks where a malicious actor could overwrite a tag with a compromised image. The digest is immutable and uniquely identifies the image content.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a vulnerability scan on the image

    Why it's wrong here

    Running a vulnerability scan enumerates known CVE identifiers in installed OS packages and libraries, but it does not validate the image's cryptographic integrity or establish its provenance. An attacker can alter the image contents to add malicious code without introducing any package vulnerability, so a clean scan does not mean the image is authentic or untampered.

  • ✗

    Use the latest tag to ensure the most recent version

    Why it's wrong here

    The latest tag is a mutable pointer that repository users and CI pipelines can overwrite at any time, so pulling latest does not cause you to fetch a specific, immutable artifact. Even if the most recent version is desired, there is no way to verify that the tag's current content came from a trusted publisher, because tag resolution is not authenticated.

  • ✗

    Generate an SBOM for the image

    Why it's wrong here

    An SBOM is a structured inventory of software components and their versions, generated either from the image or its build process, but it does not provide a cryptographically bound verification of the image's integrity or origin. Because SBOMs describe what is present rather than proving the content was not modified in transit or in the registry, they are an attestation aid, not an integrity check.

  • ✓

    Use the image digest (SHA256) instead of a tag

    Why this is correct

    Using the image digest (e.g., myrepo/app@sha256:…) pins the pull to the exact content-addressed manifest, so any tampering or tag re-pointing produces a different hash and breaks the reference. This defeats tag-mutability and re-tagging attacks, but note the digest is verified against the registry's copy; it does not independently prove the publisher's identity, which is why it is often combined with signatures.

  • ✓

    Verify the image signature using Cosign

    Why this is correct

    Cosign attaches a cryptographic signature to the image's manifest, and verification checks that signature against an expected public key or a keyless Fulcio/Rekor chain. If the image or its tag is mutated after signing, the signature fails validation, proving both the signer's identity and the integrity of the exact manifest contents.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.