Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Certified Kubernetes Security Specialist (CKS)

Domain 4Objective 2

Detect Threats Within Physical Infrastructure, Apps, Networks, Data, Users and Workloads CKS Practice Questions (Page 1)

Part of the Supply Chain Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
7concepts
20%of the exam

Questions 1–5

  1. 1application · medium

    A DevOps engineer notices that a service account used by a CI/CD pipeline has suddenly started authenticating from an IP address in a different country and is pulling container images at an unusually high rate. The engineer wants to detect whether this is a compromised credential or a legitimate change. Which combination of signals should be correlated to make this determination?

    Select an answer first
  2. 2application · medium

    A security analyst is reviewing network traffic logs and notices a series of connection attempts to multiple ports on the same internal IP address from a single source. The attempts occur in rapid succession. This pattern is characteristic of which type of threat?

    Select an answer first
  3. 3application · medium

    A security analyst is investigating a potential data breach. They notice that a large amount of data has been transferred from an internal database to an external IP address over the network. Which detection mechanism would have been most effective in identifying this exfiltration?

    Select an answer first
  4. 4expert · hard

    A security team is investigating a potential application-level attack. They notice that a containerized application is making unexpected system calls and accessing files outside its expected scope. They want to determine if this is a code injection attack or a misconfiguration. Which approach should they take?

    Select an answer first
  5. 5foundation · easy

    Which activity is an example of workload threat detection in a containerized environment?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.