
Certified Kubernetes Security Specialist (CKS)
Domain 4Objective 2
Detect Threats Within Physical Infrastructure, Apps, Networks, Data, Users and Workloads CKS Practice Questions (Page 5)
Part of the Supply Chain Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
7concepts
20%of the exam
Questions 21–25
- 21
A company operates a Kubernetes cluster in a data center that is shared with other tenants. They are concerned about hardware tampering by other tenants who have physical access to the servers. They want to detect if a server's hardware has been modified. Which detection method is most appropriate given the shared environment?
Select an answer first - 22
What is a common indicator of malware execution within a container?
Select an answer first - 23
What is a common indicator of command-and-control (C2) communication in network traffic?
Select an answer first - 24
Which method is commonly used to detect unauthorized physical access to a data center?
Select an answer first - 25
A security engineer is investigating a compromised container in a Kubernetes cluster. The container is running a web server and has been observed spawning a shell process and making outbound connections. Which detection tool would have been most effective in identifying this behavior?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.