
Certified Kubernetes Security Specialist (CKS)
Domain 2Objective 2
Understand Your Supply Chain (e.g. SBOM, CI/CD, Artifact Repositories) CKS Practice Questions (Page 2)
Part of the Minimize Microservice Vulnerabilities domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
20%of the exam
Questions 6–10
- 6
What is the purpose of signing software artifacts?
Select an answer first - 7
Which tool is commonly used to generate an SBOM for a container image?
Select an answer first - 8
Your security team receives an SBOM file from a third-party vendor for a library you plan to use. Before trusting the SBOM, you need to ensure it has not been tampered with and that it genuinely corresponds to the library artifact. Which action should you take first?
Select an answer first - 9
What is a malicious image in the context of supply chain security?
Select an answer first - 10
What is the purpose of verifying the integrity of an SBOM?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.