Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

You need to sign a container image using cosign with a key stored in an environment variable. Which command should you use?

⚠ Common exam trap

The CKS exam often tests the distinction between shell variable expansion (`$VAR`) and Cosign's native `env://` URI scheme, tricking candidates into thinking that simply passing the variable value as an argument is sufficient, when in fact the `env://` prefix is required for secure key retrieval.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

cosign sign --key env://COSIGN_PRIVATE_KEY myimage:latest

`cosign sign --key env://COSIGN_PRIVATE_KEY` instructs Cosign to read the private key from the environment variable named `COSIGN_PRIVATE_KEY` using the `env://` URI scheme. This is the standard way to reference a key stored in an environment variable, avoiding exposure on the command line or in files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    cosign sign myimage:latest --key cosign.pub

    Why it's wrong here

    cosign sign myimage:latest --key cosign.pub is invalid because it attempts to sign using a public key. The .pub file contains only public parameters, which are sufficient for verifying a signature but mathematically cannot produce one. Signing requires the private key (typically cosign.key), so this command fails or generates a useless signature because the private exponent is never supplied.

  • ✓

    cosign sign --key env://COSIGN_PRIVATE_KEY myimage:latest

    Why this is correct

    cosign sign --key env://COSIGN_PRIVATE_KEY myimage:latest is the correct syntax for supplying a private key from an environment variable. The env:// URI scheme tells cosign to interpret COSIGN_PRIVATE_KEY as the name of an environment variable whose value contains the actual key material, rather than as a file system path. This approach keeps the private key out of the filesystem and out of the visible command line, which is the intended method for in-memory key handling with cosign.

  • ✗

    cosign sign --key $COSIGN_PRIVATE_KEY myimage:latest

    Why it's wrong here

    cosign sign --key $COSIGN_PRIVATE_KEY myimage:latest is wrong because the shell expands the variable before cosign executes. Cosign then receives the entire PEM key content as the --key argument and tries to treat that string as a file path, which almost certainly does not exist. This also leaks the private key into the process listing, making it a bad practice for security-sensitive environments.

  • ✗

    cosign sign --key file://cosign.key myimage:latest

    Why it's wrong here

    cosign sign --key file://cosign.key myimage:latest is incorrect for this task because file:// designates a local file path, not an environment variable. Although cosign supports file:// URIs for key files, the requirement explicitly asks to use a key from an environment variable (env://). This command would attempt to load a file named cosign.key from disk, completely ignoring the environment variable and likely failing if that file is absent or does not match the intended key.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.