Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium
A development team is deploying a new application to a Kubernetes cluster. They want to ensure that all container images used in their deployments originate from an approved, scanned registry and have not been tampered with since being built. Which security control directly addresses this requirement by verifying the integrity and origin of container images before they are allowed to run?
- APod Security Context
- BService Mesh
- CImage Signing and Verification
- DNetworkPolicy
Show answer & explanationAnswer & explanation
Correct answer: C. Image Signing and Verification
Image signing and verification is a critical supply chain security measure that ensures the integrity and authenticity of container images. It prevents the deployment of untrusted or tampered images by cryptographic validation.
Why the other options are wrong
- A. Pod Security Context defines security privileges and access controls for pods and containers, but not image verification.
- B. A Service Mesh manages communication between services, providing features like traffic management and observability, not image integrity checks.
- D. NetworkPolicy controls network traffic flow within the cluster, not image origin or integrity.
Image Signing & Verification
A security practice where container images are cryptographically signed by trusted entities (e.g., CI/CD pipelines) and then verified before deployment to ensure their authenticity and integrity.
- Uses digital signatures to prove image origin.
- Ensures images have not been tampered with.
- Prevents supply chain attacks via malicious images.
Memory trick: Sign your images, verify your trust, prevent the bust!