Courseiva
Supply Chain Security →mediumMultiple Select

CKS Supply Chain Security Practice Question

Which TWO of the following tools can be used to generate or analyze SBOMs? (Select 2)

⚠ Common exam trap

The CKS exam, part of the CNCF certification, often tests the distinction between tools that perform SBOM generation/analysis versus tools that handle other supply chain security tasks like signing (Cosign) or static configuration scanning (Kubesec, Checkov), leading candidates to confuse vulnerability scanning with SBOM functionality.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Syft

Syft is a CLI tool specifically designed to generate Software Bill of Materials (SBOMs) from container images and filesystems. It supports multiple output formats such as CycloneDX and SPDX, making it a direct choice for SBOM generation. Trivy, while primarily a vulnerability scanner, also includes built-in SBOM generation and analysis capabilities, allowing users to output SBOMs in CycloneDX or SPDX formats and to scan existing SBOMs for vulnerabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cosign

    Why it's wrong here

    Cosign signs and verifies container images and attestations; it consumes SBOMs as attestation predicates but neither generates nor analyses them. It is tempting because it sits in the same supply-chain security toolchain, and it would be correct if the question asked how to sign or verify an SBOM attestation.

  • ✗

    Kubesec

    Why it's wrong here

    Kubesec scores Kubernetes manifests against security risks such as privileged containers and missing resource limits; it never parses dependency trees, so it cannot produce or read an SBOM. It is tempting because it is a supply-chain security tool, and it would be the right choice for admission-time manifest hardening.

  • ✓

    Syft

    Why this is correct

    Syft generates software bills of materials by scanning container images and filesystems, cataloguing packages and their versions into SPDX or CycloneDX formats. This directly satisfies the stem's requirement to generate SBOMs, complementing analysis tools that consume that output.

  • ✓

    Trivy

    Why this is correct

    Trivy scans container images and filesystems to produce SPDX or CycloneDX SBOMs, and can also analyse existing ones for vulnerabilities. This directly satisfies the stem's requirement for a tool that both generates and analyses SBOMs, covering the software supply chain visibility that CKS expects.

  • ✗

    Checkov

    Why it's wrong here

    Checkov is a static analysis tool for infrastructure-as-code misconfiguration, producing no SBOM output and parsing no package manifests. It is tempting because it is a security scanning tool used in CI pipelines, and it would be correct if the question asked which tool detects misconfigured Terraform or Kubernetes manifests.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.