Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Certified Kubernetes Security Specialist (CKS)

Domain 6Objective 2

Detect Threats Within Physical Infrastructure, Apps, Networks, Data, Users and Workloads CKS Practice Questions (Page 3)

Part of the Monitoring, Logging and Runtime Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
7concepts
20%of the exam

Questions 11–15

  1. 11expert · hard

    A security analyst is investigating a potential data breach. They find that a pod in the 'payment' namespace has been writing to a file in a mounted volume that is not part of its expected application behavior. The pod's application is a Java-based payment processor. The file is being written to a path that is also accessible by another pod in the same namespace. What is the most likely threat this behavior indicates?

    Select an answer first
  2. 12foundation · easy

    Which of the following is an example of a workload threat in a Kubernetes cluster?

    Select an answer first
  3. 13foundation · easy

    Which of the following is a sign of a physical infrastructure threat on a Kubernetes node?

    Select an answer first
  4. 14application · medium

    A security team is reviewing audit logs and finds that a pod running with the 'default' service account executed 'chmod 4755 /bin/sh' and then spawned a new shell process. The pod's container image is a standard 'ubuntu' image and the application inside is a simple web server. What is the most likely threat this activity represents?

    Select an answer first
  5. 15expert · hard

    A security team is investigating a potential data breach. They notice that a pod in the 'analytics' namespace has been reading a large number of files from a mounted volume that contains customer data. The pod's legitimate function is to process aggregated data, not raw customer data. What is the most likely threat this behavior indicates?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.