
Certified Kubernetes Application Developer (CKAD)
Domain 4Objective 2
Kubernetes Security CKAD Practice Questions (Page 4)
Part of the Application Environment, Configuration and Security domain, which accounts for 25% of the CKAD exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 3–5 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
12concepts
25%of the exam
Questions 16–20
- 16
What does a SecurityContext allow you to configure at the pod level?
Select an answer first - 17
How are Pod Security Standards typically applied to a namespace?
Select an answer first - 18
You have a CronJob that needs to list all pods in the cluster. You have created a ServiceAccount named 'cluster-pod-reader' and a ClusterRole that grants 'list' on 'pods' cluster-wide. What must you do to grant the ServiceAccount these permissions?
Select an answer first - 19
Which of the following is a valid Linux capability that can be added to a container?
Select an answer first - 20
A pod in your cluster needs to authenticate to the Kubernetes API server to list pods in its own namespace. You have created a ServiceAccount named 'pod-reader' and bound a Role to it. What must you do to ensure the pod can use this ServiceAccount's token for authentication?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKAD” is a trademark of its owner, used for identification only.