Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

You run 'trivy image myapp:latest' and the scan reports several critical CVEs. What is the best action to take?

⚠ Common exam trap

A common misconception is that deleting the pod or image is sufficient remediation, when the correct action is to patch the image at the source and re-deploy to eliminate the vulnerability from the running environment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rebuild the image with updated base images and re-deploy

Rebuilding the image with updated base images directly addresses the root cause of the CVEs—outdated or vulnerable packages in the container image. After rebuilding, you must re-deploy the updated image to replace the running vulnerable containers. This aligns with the supply chain security principle of maintaining a secure software bill of materials (SBOM) and ensuring images are patched against known vulnerabilities before deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use kubectl delete pod to remove the running container

    Why it's wrong here

    Deleting the pod only terminates the current instance; the vulnerable image remains in the cluster's local cache or registry and will be reused on redeployment. This does not address the underlying vulnerability or patch the image layers, leaving the cluster exposed when the pod is recreated by a Deployment or ReplicaSet.

  • ✗

    Delete the image from the registry

    Why it's wrong here

    Removing the image from the registry does not affect copies already pulled onto nodes; the container runtime still has the vulnerable image layers cached. It also doesn't remediate running containers or alter any existing workload manifests that reference the image. The image must be rebuilt and redeployed to ensure nodes pull the patched version.

  • ✓

    Rebuild the image with updated base images and re-deploy

    Why this is correct

    Rebuilding the image with updated base images ensures that the vulnerable layers are replaced with patched versions, eliminating the reported CVEs. After rebuilding, re-deploying the workload (e.g., by updating the Deployment's image tag) forces nodes to pull the new image and run a clean container. This is the correct remediation because it addresses the root cause—vulnerable dependencies in the image—rather than mitigating symptoms.

  • ✗

    Ignore the CVEs because the image is running in a non-production environment

    Why it's wrong here

    The severity of a CVE does not change based on the environment; critical vulnerabilities can be exploited in any context, and non-production environments may still contain sensitive data or serve as a pivot point into the network. Ignoring vulnerabilities because a system is labeled 'non-production' violates security best practices and may cause opposition from security scanning tools or admission control policies later. The correct action is to remediate regardless of environment tier.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.