
Certified Kubernetes Security Specialist (CKS)
Domain 4Objective 2
Detect Threats Within Physical Infrastructure, Apps, Networks, Data, Users and Workloads CKS Practice Questions (Page 4)
Part of the Supply Chain Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
7concepts
20%of the exam
Questions 16–20
- 16
A company stores sensitive customer data in a database. They have implemented database audit logging, but they are concerned about attackers who may have legitimate credentials and are exfiltrating data slowly over time. Which detection method would best identify this slow exfiltration?
Select an answer first - 17
Which network activity is commonly monitored to detect port scanning?
Select an answer first - 18
What is a common indicator of hardware tampering in a data center?
Select an answer first - 19
What is a common method to detect data exfiltration?
Select an answer first - 20
A system administrator notices that a user account has been granted administrative privileges and has been accessing sensitive files outside of normal business hours. The user is a contractor who was recently hired. Which detection method would best identify this as a potential insider threat?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.