Courseiva
Supply Chain Security →mediumMultiple Select

CKS Supply Chain Security Practice Question

Which TWO of the following are valid ways to verify a container image signature using cosign?

⚠ Common exam trap

The CKS exam often tests the distinction between signing (`cosign sign`, `cosign attest`) and verifying (`cosign verify`, `cosign verify-attestation`) commands, and candidates may confuse `attest` (which creates a signature) with `verify-attestation` (which checks one).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

cosign verify-attestation --key cosign.pub myimage:latest

`cosign verify-attestation --key cosign.pub myimage:latest` validates an in-toto attestation attached to a container image using a public key, which is a valid method to verify the image's provenance and integrity. Option E is correct because `cosign verify --key cosign.pub myimage:latest` directly verifies the container image's signature against the provided public key, confirming the image was signed by the holder of the corresponding private key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    cosign validate myimage:latest

    Why it's wrong here

    The `cosign validate` subcommand does not exist in the Cosign CLI. The tool's command set includes `verify` for checking image signatures and `verify-attestation` for checking in-toto attestations, but not `validate`. Running this will fail with an unknown command error, so it cannot verify anything about the image.

  • ✓

    cosign verify-attestation --key cosign.pub myimage:latest

    Why this is correct

    This command is correct because `cosign verify-attestation` checks the integrity and authenticity of an in-toto attestation attached to the image, using the provided public key (`cosign.pub`). It verifies that the attestation (e.g., SLSA provenance) was signed by the holder of the corresponding private key and has not been tampered with. This is a valid way to verify claims about an image beyond just its signature.

  • ✗

    cosign check myimage:latest

    Why it's wrong here

    There is no `cosign check` subcommand in Cosign's CLI. The verification commands are `cosign verify` for signatures and `cosign verify-attestation` for attestations, but `check` is not one of them. Attempting to run `cosign check` will simply return an error that the command is not found, making it an invalid way to verify an image.

  • ✗

    cosign attest --key cosign.key myimage:latest

    Why it's wrong here

    The command `cosign attest --key cosign.key` is used to create and sign an in-toto attestation for an image, not to verify one. It requires the private key (`cosign.key`) and writes a new attestation, whereas verification requires a public key and reads/validates an existing signature or attestation. Therefore, this command performs an operation that is the opposite of verification.

  • ✓

    cosign verify --key cosign.pub myimage:latest

    Why this is correct

    This command is correct because `cosign verify --key cosign.pub` cryptographically verifies the signature on the container image using the specified public key. It checks that the image manifest was signed by the corresponding private key and that the image has not been modified since signing. This is the standard Cosign operation for signature-only verification.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A DevOps engineer wants to ensure that a container image is signed and the signature is verified before deployment. Which Cosign command verifies an image signature?

medium
  • A.cosign sign
  • B.cosign check
  • ✓ C.cosign verify
  • D.cosign attest

Why C: The `cosign verify` command is used to check the signature of a container image against the public key that was used to sign it. This ensures the image's integrity and authenticity before deployment, which is a core requirement of the CKS Supply Chain Security domain.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.