CKS Supply Chain Security Practice Question
You need to enforce that all images deployed in the cluster are signed by a trusted key. Which Kubernetes admission control mechanism would you use?
⚠ Common exam trap
Candidates often confuse PodSecurityPolicy (which deals with pod security contexts) with image trust enforcement, but PodSecurityPolicy never validates image signatures—it only controls runtime security attributes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ImagePolicyWebhook
The ImagePolicyWebhook admission controller is specifically designed to enforce that container images are signed by a trusted key. It intercepts Pod creation requests and validates the image signatures against a configured webhook endpoint, rejecting unsigned or untrusted images. This directly addresses the requirement for supply chain security by ensuring only cryptographically verified images are deployed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ResourceQuota
Why it's wrong here
A ResourceQuota is a namespace-scoped object that enforces aggregate limits on compute resources (CPU, memory, persistent storage claims, and object counts). It does not perform admission-time validation of individual pod specifications, and it has no mechanism to inspect the image field, registry, or signature. Consequently, any container image, including an unsigned or disallowed one, can run as long as the quota's numeric limits are not exceeded.
- ✗
NetworkPolicy
Why it's wrong here
A NetworkPolicy is a Kubernetes object that controls east-west traffic by selecting pods and applying ingress/egress rules based on IP addresses and ports. It is enforced by the CNI plugin after a pod is created and operates at the network layer, never seeing the image name, registry, or signature. It cannot prevent a pod with a prohibited image from being scheduled or created; it can only restrict that pod's communications after it exists.
- ✗
PodSecurityPolicy
Why it's wrong here
PodSecurityPolicy (PSP) is a deprecated admission controller (removed in Kubernetes v1.25) that enforced security context and OS-level constraints such as disallowing privileged containers, hostPID, or hostNetwork. PSP did not have fields for validating image identity, registry, or cryptographic signatures, so even if a pod passed PSP, it could still run an arbitrary or tampered image. Its replacement, Pod Security Admission, similarly focuses on security context, not image provenance.
- ✓
ImagePolicyWebhook
Why this is correct
ImagePolicyWebhook is a Kubernetes admission controller that intercepts pod creation and sends the image references to an external HTTP(S) webhook for evaluation. This external service can verify image signatures against trusted keys, enforce allowlists of registries, or require specific digests, effectively blocking unsigned or disallowed images. Because it runs during the admission phase, it can deny a pod's creation before it is persisted, making it an appropriate tool for enforcing a cluster-wide image signature policy.
Go deeper
Related to this question
Learn chapter
Cluster Hardening: Node and Container Security
Key term
Node Restriction
A Kubernetes admission controller that limits what a kubelet can modify on its own node to prevent privilege escalation and unauthorized access.
Key term
OPA Gatekeeper
OPA Gatekeeper is a Kubernetes admission controller that enforces custom security and compliance policies on resources before they are created or updated in a cluster.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.