CCSP Cloud Platform and Infrastructure Security Practice Question
A security team is reviewing container image supply chain security. Which tool is specifically designed for signing container images to ensure integrity and provenance?
⚠ Common exam trap
CCSP often tests tool-purpose recognition — the trap is confusing vulnerability scanners (Trivy, Clair) or compliance tools (Kube-bench) with signing tools, when only Cosign provides cryptographic image signing and provenance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cosign
Cosign (C) is a tool from the Sigstore project specifically designed to sign, verify, and attach attestations to container images, providing integrity and provenance guarantees in the supply chain. It supports keyless signing via OIDC and integrates with registries and admission controllers. This makes it the purpose-built answer for image signing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Kube-bench
Why it's wrong here
Kube-bench audits Kubernetes cluster nodes against CIS benchmark configuration checks; it does not sign images or produce provenance attestations. It is tempting because it is a recognised container/Kubernetes security tool, but its function is configuration assessment, whereas signing requires a tool such as Cosign or Notary.
- ✗
Clair
Why it's wrong here
Clair performs static vulnerability scanning of container image layers against CVE databases; it neither signs images nor records provenance. It is tempting because it operates directly on container images in a supply chain pipeline, but scanning detects known vulnerabilities, whereas signing establishes integrity and origin.
- ✓
Cosign
Why this is correct
Cosign signs and verifies container images using keys or keyless OIDC identities, producing signatures that establish image integrity and provenance. It directly satisfies the supply chain requirement by letting deployments reject unsigned or tampered images before they run.
- ✗
Trivy
Why it's wrong here
Trivy is a vulnerability scanner for container images and infrastructure-as-code, not a signing tool; it cannot generate or verify cryptographic signatures to attest to image provenance, which is the core requirement for integrity in the supply chain. It is tempting because Trivy is widely used in container security pipelines for scanning known vulnerabilities (CVEs) and misconfigurations, making it the correct choice when the task is to identify security flaws in images rather than to sign them.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.