
Certified Kubernetes Security Specialist (CKS)
Domain 3Objective 4
Appropriately Use Kernel Hardening Tools Such as AppArmor, Seccomp CKS Practice Questions (Page 4)
Part of the Cluster Hardening domain, which accounts for 15% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
7concepts
15%of the exam
Questions 16–20
- 16
How can you verify that a seccomp profile is being enforced on a running container?
Select an answer first - 17
What is the effect of an AppArmor profile set to 'complain' mode?
Select an answer first - 18
A security engineer is explaining AppArmor to a colleague. Which statement accurately describes AppArmor's security model?
Select an answer first - 19
An administrator has loaded an AppArmor profile on a node, but when they try to apply it to a pod, the pod fails to start with an error that the profile is not found. The profile is definitely loaded. What is a possible cause?
Select an answer first - 20
A pod is running with a seccomp profile that restricts system calls. The application inside the pod is failing with `Operation not permitted` errors. The administrator wants to verify that the seccomp profile is actually being applied. Which command or method should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.