
Certified Kubernetes Security Specialist (CKS)
Domain 1Objective 3
Access Control CKS Practice Questions (Page 4)
Part of the Cluster Setup domain, which accounts for 15% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
10concepts
15%of the exam
Questions 16–20
- 16
Why is the principle of least privilege important in Kubernetes RBAC?
Select an answer first - 17
What is the purpose of OIDC authentication in Kubernetes?
Select an answer first - 18
Which of the following is a valid method to restrict access to the Kubernetes API server?
Select an answer first - 19
A Pod in the 'backend' namespace runs a batch job that needs to authenticate to the Kubernetes API once at startup. The Pod's ServiceAccount token is long-lived. You want to reduce the risk of token theft. What is the most effective configuration change?
Select an answer first - 20
What is the primary difference between a ClusterRole and a Role in Kubernetes RBAC?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.