CKS Supply Chain Security Practice Question
You are the lead security engineer for a large financial institution. The organization runs a Kubernetes cluster with 500+ microservices. The supply chain security team has implemented the following measures: (1) All images are built from a minimal base image (distroless) and scanned with Trivy before being pushed to a private registry. (2) Images are signed using cosign with a key stored in a hardware security module (HSM). (3) Kyverno policies enforce that only signed images from the private registry can run, and also enforce that containers run as non-root. (4) A binary authorization (binauthz) style admission controller verifies attestations. Recently, a critical vulnerability (CVE-2024-0001) was discovered in a popular open-source library used by several microservices. The library is included as a dependency in the base image. The vulnerability is remotely exploitable and has a CVSS score of 9.8. The security team needs to remediate this quickly. They have already patched the library and updated the base image. What is the BEST course of action to ensure all running pods use the new image?
⚠ Common exam trap
CNCF often tests the misconception that manual intervention (SSH, exec) or disabling security controls is acceptable for urgent fixes, when in fact the correct path is to update the deployment manifest and let Kubernetes orchestrate the change while keeping all security checks active.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the image tag in each Deployment's spec to point to the new patched image, then perform a rolling update. The admission controller will verify signatures and attestations for the new image.
Updating the image tag in each Deployment triggers a rolling update, which creates new pods with the patched image. The admission controller (Kyverno) will verify the cosign signature and binary authorization attestation for the new image, ensuring supply chain security is maintained. This approach is the standard Kubernetes method for deploying image updates while preserving security controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Update the image tag in each Deployment's spec to point to the new patched image, then perform a rolling update. The admission controller will verify signatures and attestations for the new image.
Why this is correct
Updating the image tag in each Deployment's PodTemplateSpec is the correct declarative approach: it triggers a rolling replacement of the underlying ReplicaSets, so old pods are terminated only after new ones become Ready. During pod creation, the cluster's validating/mutating admission controller (e.g., Kyverno or OPA via cosign) checks the image's cryptographic signature and attestations; if the patched image is signed and passes policy, the update proceeds. This ensures every pod runs a verified, patched image with zero downtime.
- ✗
SSH into each node, pull the new image, and use kubectl exec to update the library inside running containers.
Why it's wrong here
SSHing into nodes and editing files inside running containers fundamentally breaks the container immutability principle and the changes are lost on any restart or reschedule because they are not captured in the image or the pod spec. Furthermore, kubectl exec only affects a live container; the node still holds the original image and the kubelet will never re-pull the new image for existing pods, so the vulnerability remains on any new replica. This is also operationally unscalable and violates security best practices like immutable infrastructure and traceable configuration.
- ✗
Temporarily disable the admission controller that verifies signatures and then update the image tags.
Why it's wrong here
Temporarily removing the admission control check creates a window during which any image—even one that is malicious or unverified—can be deployed, undermining the entire supply chain security model. Even if you re-enable it afterwards, the deployment that goes through during the disabled period is never scrutinized, and you might accidentally leave the policy off in a production cluster. The correct behavior is to keep image verification active and ensure the patched image meets the established signature and attestation requirements, as disabling policy for convenience is a common security anti-pattern.
- ✗
Delete all running pods and let the ReplicaSets recreate them from the existing image.
Why it's wrong here
Deleting all pods does not alter the image reference stored in each ReplicaSet's PodTemplate; the ReplicaSet controller will simply recreate pods with the exact same vulnerable image, and you'll have incurred downtime for zero remediation. This is equivalent to a hard restart, not an update, and it lacks the gradual, health-checked rollout that a Deployment rolling update provides. Without changing the Deployment's spec, the cluster will keep using the old, unpatched container image indefinitely.
Go deeper
Related to this question
Learn chapter
Kubernetes Security Fundamentals
Key term
OPA Gatekeeper
OPA Gatekeeper is a Kubernetes admission controller that enforces custom security and compliance policies on resources before they are created or updated in a cluster.
Key term
Image Scanning
Image scanning is the automated process of inspecting container images for known vulnerabilities, misconfigurations, and malware before they are deployed into production environments.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.