Courseiva
Supply Chain Security →mediumMultiple Select

CKS Supply Chain Security Practice Question

Which TWO tools can generate an SBOM for a container image? (Select two.)

⚠ Common exam trap

The CNCF CKS exam often tests the distinction between tools that generate SBOMs (Trivy, Syft) versus tools that scan for vulnerabilities (Trivy can do both, but the question specifically asks for SBOM generation) or perform other supply chain tasks like signing (Cosign) or IaC scanning (Checkov), leading candidates to confuse a tool's primary function with its secondary capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

trivy

Trivy is a comprehensive vulnerability scanner that can generate an SBOM (Software Bill of Materials) for container images using its `trivy image --format cyclonedx` or `trivy image --format spdx` commands, outputting in CycloneDX or SPDX formats. Syft is a dedicated SBOM generation tool from Anchore that produces detailed SBOMs from container images using `syft packages <image>` and supports multiple output formats including CycloneDX and SPDX. Both tools are specifically designed to inventory all software components within a container image, making them correct choices for SBOM generation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    checkov

    Why it's wrong here

    Checkov is a static analysis tool for Infrastructure-as-Code (IaC) that scans Terraform, CloudFormation, and Kubernetes manifest files. It evaluates configurations against a library of policies for misconfigurations and compliance, but it never inspects the contents of a container image or its package metadata. Therefore it cannot produce an SBOM, which requires enumerating the software components inside an image.

  • ✓

    trivy

    Why this is correct

    Trivy is a container security scanner that also generates SBOMs in multiple formats, including CycloneDX and SPDX. Using subcommands like `trivy image --format cyclonedx` or `trivy sbom`, it extracts package information from the image's layers and package databases (e.g., dpkg, RPM, and ERS). This dual functionality makes Trivy a go-to tool for both vulnerability scanning and SBOM production.

  • ✓

    syft

    Why this is correct

    Syft is a dedicated software-bill-of-materials generation tool from Anchore that focuses solely on cataloging components from container images and filesystem paths. It performs deep extraction of package managers and known file formats, such as dpkg, RPM, apk, go.mod, and requirements.txt, and outputs SBOMs in CycloneDX, SPDX, or JSON. Unlike vulnerability scanners, Syft is engineered specifically for accurate and fast SBOM creation.

  • ✗

    cosign

    Why it's wrong here

    Cosign is part of the Sigstore project and is primarily used to sign and verify container images, blobs, and other artifacts with keyless signing or a private key. It can attach and store SBOMs as artifact attestations or in a registry in-toto envelope, but it does not analyze the image itself. Since Cosign cannot extract package manifests or component lists, it is not an SBOM generator.

  • ✗

    kubesec

    Why it's wrong here

    Kubesec is a Kubernetes manifest scanner that rates YAML files against security best practices, such as preventing privileged containers, enforcing read-only root filesystems, and setting resource limits. It operates purely on declarative object definitions and never inspects the corresponding container image layers or installed software. Thus it has no ability to generate an SBOM.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.