Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

You need to enforce that all images deployed in the cluster are signed by a trusted key. Which Kubernetes admission control mechanism would you use?

⚠ Common exam trap

Candidates often confuse PodSecurityPolicy (which deals with pod security contexts) with image trust enforcement, but PodSecurityPolicy never validates image signatures—it only controls runtime security attributes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ImagePolicyWebhook

The ImagePolicyWebhook admission controller is specifically designed to enforce that container images are signed by a trusted key. It intercepts Pod creation requests and validates the image signatures against a configured webhook endpoint, rejecting unsigned or untrusted images. This directly addresses the requirement for supply chain security by ensuring only cryptographically verified images are deployed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ResourceQuota

    Why it's wrong here

    A ResourceQuota is a namespace-scoped object that enforces aggregate limits on compute resources (CPU, memory, persistent storage claims, and object counts). It does not perform admission-time validation of individual pod specifications, and it has no mechanism to inspect the image field, registry, or signature. Consequently, any container image, including an unsigned or disallowed one, can run as long as the quota's numeric limits are not exceeded.

  • ✗

    NetworkPolicy

    Why it's wrong here

    A NetworkPolicy is a Kubernetes object that controls east-west traffic by selecting pods and applying ingress/egress rules based on IP addresses and ports. It is enforced by the CNI plugin after a pod is created and operates at the network layer, never seeing the image name, registry, or signature. It cannot prevent a pod with a prohibited image from being scheduled or created; it can only restrict that pod's communications after it exists.

  • ✗

    PodSecurityPolicy

    Why it's wrong here

    PodSecurityPolicy (PSP) is a deprecated admission controller (removed in Kubernetes v1.25) that enforced security context and OS-level constraints such as disallowing privileged containers, hostPID, or hostNetwork. PSP did not have fields for validating image identity, registry, or cryptographic signatures, so even if a pod passed PSP, it could still run an arbitrary or tampered image. Its replacement, Pod Security Admission, similarly focuses on security context, not image provenance.

  • ✓

    ImagePolicyWebhook

    Why this is correct

    ImagePolicyWebhook is a Kubernetes admission controller that intercepts pod creation and sends the image references to an external HTTP(S) webhook for evaluation. This external service can verify image signatures against trusted keys, enforce allowlists of registries, or require specific digests, effectively blocking unsigned or disallowed images. Because it runs during the admission phase, it can deny a pod's creation before it is persisted, making it an appropriate tool for enforcing a cluster-wide image signature policy.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.