CKS Supply Chain Security Practice Question
Which TWO tools can generate an SBOM for a container image? (Select two.)
⚠ Common exam trap
The CNCF CKS exam often tests the distinction between tools that generate SBOMs (Trivy, Syft) versus tools that scan for vulnerabilities (Trivy can do both, but the question specifically asks for SBOM generation) or perform other supply chain tasks like signing (Cosign) or IaC scanning (Checkov), leading candidates to confuse a tool's primary function with its secondary capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
trivy
Trivy is a comprehensive vulnerability scanner that can generate an SBOM (Software Bill of Materials) for container images using its `trivy image --format cyclonedx` or `trivy image --format spdx` commands, outputting in CycloneDX or SPDX formats. Syft is a dedicated SBOM generation tool from Anchore that produces detailed SBOMs from container images using `syft packages <image>` and supports multiple output formats including CycloneDX and SPDX. Both tools are specifically designed to inventory all software components within a container image, making them correct choices for SBOM generation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
checkov
Why it's wrong here
Checkov is a static analysis tool for Infrastructure-as-Code (IaC) that scans Terraform, CloudFormation, and Kubernetes manifest files. It evaluates configurations against a library of policies for misconfigurations and compliance, but it never inspects the contents of a container image or its package metadata. Therefore it cannot produce an SBOM, which requires enumerating the software components inside an image.
- ✓
trivy
Why this is correct
Trivy is a container security scanner that also generates SBOMs in multiple formats, including CycloneDX and SPDX. Using subcommands like `trivy image --format cyclonedx` or `trivy sbom`, it extracts package information from the image's layers and package databases (e.g., dpkg, RPM, and ERS). This dual functionality makes Trivy a go-to tool for both vulnerability scanning and SBOM production.
- ✓
syft
Why this is correct
Syft is a dedicated software-bill-of-materials generation tool from Anchore that focuses solely on cataloging components from container images and filesystem paths. It performs deep extraction of package managers and known file formats, such as dpkg, RPM, apk, go.mod, and requirements.txt, and outputs SBOMs in CycloneDX, SPDX, or JSON. Unlike vulnerability scanners, Syft is engineered specifically for accurate and fast SBOM creation.
- ✗
cosign
Why it's wrong here
Cosign is part of the Sigstore project and is primarily used to sign and verify container images, blobs, and other artifacts with keyless signing or a private key. It can attach and store SBOMs as artifact attestations or in a registry in-toto envelope, but it does not analyze the image itself. Since Cosign cannot extract package manifests or component lists, it is not an SBOM generator.
- ✗
kubesec
Why it's wrong here
Kubesec is a Kubernetes manifest scanner that rates YAML files against security best practices, such as preventing privileged containers, enforcing read-only root filesystems, and setting resource limits. It operates purely on declarative object definitions and never inspects the corresponding container image layers or installed software. Thus it has no ability to generate an SBOM.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.