Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Certified Kubernetes Security Specialist (CKS)

Domain 2Objective 2

Understand Your Supply Chain (e.g. SBOM, CI/CD, Artifact Repositories) CKS Practice Questions (Page 6)

Part of the Minimize Microservice Vulnerabilities domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
7concepts
20%of the exam

Questions 26–28

  1. 26foundation · easy

    What is 'provenance' in the context of software supply chain security?

    Select an answer first
  2. 27expert · hard

    Your CI/CD pipeline builds a container image and pushes it to a registry. You want to ensure that the image is built from source code that has been reviewed and approved, and that the image itself is not tampered with after the build. You have limited time to implement a solution. Which approach provides the strongest assurance with the least overhead?

    Select an answer first
  3. 28application · medium

    Your team uses a CI/CD pipeline to build a Java application. You need to produce a machine-readable SBOM that can be automatically consumed by your security tooling and that supports component-level vulnerability tracking. Which format and tool combination is most appropriate?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CKS

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.