Valid KCSA Dumps shared by ExamDiscuss.com for Helping Passing KCSA Exam! ExamDiscuss.com now offer the newest KCSA exam dumps, the ExamDiscuss.com KCSA exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com KCSA dumps with Test Engine here:
Which information does a user need to verify a signed container image?
Correct Answer: D
* Container image signing (e.g., withcosign, Notary v2) uses asymmetric cryptography. * Verification process: * Retrieve theimage's digital signature. * Validate the signature with thepublic keyof the signer. * Exact extract (Sigstore Cosign Docs): * "Verification of an image requires the signature and the signer's public key. The signature proves authenticity and integrity." * Why others are wrong: * A & B: The private key is only used by the signer, never shared. * C: The hash alone cannot prove authenticity without the digital signature. References: Sigstore Cosign Docs: https://docs.sigstore.dev/cosign/overview