Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Certified Kubernetes Security Specialist (CKS)

Domain 6Objective 2

Detect Threats Within Physical Infrastructure, Apps, Networks, Data, Users and Workloads CKS Practice Questions (Page 2)

Part of the Monitoring, Logging and Runtime Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
7concepts
20%of the exam

Questions 6–10

  1. 6foundation · easy

    Which of the following is an example of a threat that targets the physical infrastructure layer of a Kubernetes deployment?

    Select an answer first
  2. 7foundation · easy

    Which of the following is an example of a threat that targets the data plane of a Kubernetes cluster?

    Select an answer first
  3. 8application · medium

    A security team is using Falco to monitor container activity. They receive an alert that a process inside a container is trying to execute a binary from a mounted hostPath directory. The container's legitimate application is a Python web server. What is the most likely threat this alert indicates?

    Select an answer first
  4. 9application · medium

    A cluster administrator is investigating a potential data breach. They notice that a pod in the 'finance' namespace has been making large outbound data transfers to an IP address in a foreign country. The pod's legitimate function is to process internal payroll data and should not have any external network access. What is the most likely threat this behavior indicates?

    Select an answer first
  5. 10expert · hard

    A security analyst is reviewing audit logs and notices that a service account 'ci-bot' has been creating and deleting pods in the 'staging' namespace at a very high frequency. The 'ci-bot' is supposed to only trigger deployments during business hours. The activity is happening at 2:00 AM. What is the most likely threat this behavior indicates?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.