Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A security team is reviewing container image supply chain security. Which tool is specifically designed for signing container images to ensure integrity and provenance?

⚠ Common exam trap

CCSP often tests tool-purpose recognition — the trap is confusing vulnerability scanners (Trivy, Clair) or compliance tools (Kube-bench) with signing tools, when only Cosign provides cryptographic image signing and provenance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cosign

Cosign (C) is a tool from the Sigstore project specifically designed to sign, verify, and attach attestations to container images, providing integrity and provenance guarantees in the supply chain. It supports keyless signing via OIDC and integrates with registries and admission controllers. This makes it the purpose-built answer for image signing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Kube-bench

    Why it's wrong here

    Kube-bench audits Kubernetes cluster nodes against CIS benchmark configuration checks; it does not sign images or produce provenance attestations. It is tempting because it is a recognised container/Kubernetes security tool, but its function is configuration assessment, whereas signing requires a tool such as Cosign or Notary.

  • ✗

    Clair

    Why it's wrong here

    Clair performs static vulnerability scanning of container image layers against CVE databases; it neither signs images nor records provenance. It is tempting because it operates directly on container images in a supply chain pipeline, but scanning detects known vulnerabilities, whereas signing establishes integrity and origin.

  • ✓

    Cosign

    Why this is correct

    Cosign signs and verifies container images using keys or keyless OIDC identities, producing signatures that establish image integrity and provenance. It directly satisfies the supply chain requirement by letting deployments reject unsigned or tampered images before they run.

  • ✗

    Trivy

    Why it's wrong here

    Trivy is a vulnerability scanner for container images and infrastructure-as-code, not a signing tool; it cannot generate or verify cryptographic signatures to attest to image provenance, which is the core requirement for integrity in the supply chain. It is tempting because Trivy is widely used in container security pipelines for scanning known vulnerabilities (CVEs) and misconfigurations, making it the correct choice when the task is to identify security flaws in images rather than to sign them.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.