TechNuggets Academy

Supply Chain Security

Free Certified Kubernetes Security Specialist practice — 6 questions on Supply Chain Security, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Supply Chain Security
Your security team requires that the API server admit only container images from a trusted internal registry, and mandates using a native Kubernetes admission mechanism rather than deploying any third-party controller. Which mechanism should you configure on the API server?
ImagePolicyWebhook is a built-in kube-apiserver admission plugin enabled with --enable-admission-plugins=ImagePolicyWebhook and configured via an AdmissionConfiguration file pointing to a webhook backend that decides whether an image reference is allowed. It requires no third-party controller to be installed in the cluster.
Question 2 of 6 · Supply Chain Security
A CI pipeline stage runs: trivy image --exit-code 1 --severity CRITICAL myapp:v2. The scan finds 3 CRITICAL and 5 HIGH severity vulnerabilities. What happens to the pipeline stage?
The --severity CRITICAL flag limits which findings trivy counts, and --exit-code 1 tells trivy to return exit code 1 if any vulnerabilities matching that filter are found. Since 3 CRITICAL vulnerabilities were found, trivy exits with 1 and most CI systems treat a non-zero exit code as a failed stage.
Question 3 of 6 · Supply Chain Security
Your CI pipeline signs container images using Sigstore keyless signing (Fulcio short-lived certificates plus Rekor transparency log entries). Before Kubernetes admits a Pod, you need to cryptographically verify these signatures against expected certificate identity and OIDC issuer. Which tool and command should you use?
cosign is the Sigstore project's client tool and natively supports keyless verification. cosign verify --certificate-identity=<expected-signer> --certificate-oidc-issuer=<expected-issuer> <image> checks the Fulcio-issued certificate embedded in the signature and confirms the Rekor transparency log entry, confirming the image was signed by the expected CI identity.
Question 4 of 6 · Supply Chain Security
You need to scan a Kubernetes Pod manifest with kubesec for security misconfigurations, but organizational policy prohibits sending manifest data to any external network endpoint. Which approach satisfies this requirement?
kubesec ships as a standalone Go binary (and container image) that evaluates manifests entirely locally, producing a JSON risk score with no network calls required — satisfying an offline/air-gapped policy constraint.
Question 5 of 6 · Supply Chain Security
What is the primary supply-chain security benefit of using a 'distroless' base image (e.g., gcr.io/distroless/static) compared to a minimal Alpine-based image?
Distroless images strip out shells, package managers (apk/apt), and most coreutils, leaving only the application and its runtime dependencies. Even if an attacker exploits an application vulnerability and gains code execution, there is no shell or package manager available to pivot, install tools, or explore the filesystem interactively — significantly reducing post-compromise capability.
Question 6 of 6 · Supply Chain Security
A compliance requirement mandates generating a Software Bill of Materials (SBOM) for every container image, in a standardized schema consumable by both vulnerability scanners and license-compliance tooling. Which CI pipeline command correctly produces this artifact?
syft is purpose-built to generate SBOMs by cataloging packages, libraries, and metadata inside an image, and -o cyclonedx-json emits it in the CycloneDX standard schema — an industry format understood by downstream vulnerability scanners (e.g., grype) and license-compliance tools.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →