Courseiva
Supply Chain Security →hardMultiple Choice

CKS Supply Chain Security Practice Question

You have a Kyverno policy that validates image registries. The policy should allow only images from `myregistry.example.com`. Which Kyverno rule field should be used to check the image registry?

⚠ Common exam trap

Candidates often confuse `imageRegistry` with `resources` or think validation is done via `mutate`, but only `imageRegistry` directly checks the registry portion of the container image reference.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

imageRegistry

The `imageRegistry` field in a Kyverno policy rule is specifically designed to validate image registries by matching the registry hostname against a pattern. In this case, setting `imageRegistry: "myregistry.example.com/*"` ensures only images from that registry are allowed, blocking others at admission time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    mutate

    Why it's wrong here

    Kyverno's `mutate` rule type is designed to modify incoming resources before admission, such as adding labels, injecting sidecars, or rewriting image tags. It does not perform validation checks and cannot deny a resource based on image registry policy. Even if you combine `mutate` with conditional anchors to mimic a check, it will still apply the mutation rather than block non-compliant images. For enforcing allowed registries, you must use the `validate` rule type with `imageRegistry` or a deny condition.

  • ✗

    resources

    Why it's wrong here

    The `resources` field in a Kyverno rule acts as a selector to scope the rule to specific kinds, names, namespaces, or label/annotation sets. It determines which Kubernetes resources are subject to the rule, but it does not itself define any validation logic. When seeking to validate image registries, you still need a `validate` rule that targets Pods and checks image references; `resources` alone cannot enforce or reject anything, it only narrows the rule's applicability.

  • ✓

    imageRegistry

    Why this is correct

    `imageRegistry` is a dedicated field inside a Kyverno `validate` rule that defines a list of allowed image registries (e.g., `registry.mycompany.com/*`). When a target resource like a Pod is created or updated, Kyverno evaluates all container image references against this allowlist and denies admission if any image comes from a registry outside the list. This is the correct and direct way to enforce image registry validation, making it the answer for this question.

  • ✗

    generate

    Why it's wrong here

    Kyverno's `generate` rule type creates supplementary Kubernetes resources (e.g., ConfigMaps, NetworkPolicies, or ServiceAccounts) based on a trigger resource, and it can even synchronize changes to generated resources. It is purely a resource-generation mechanism and does not inspect or validate images already present in incoming admission requests. To enforce image registry restrictions, you need a validation rule; `generate` would not block or permit anything related to image registries.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.