
Certified Kubernetes Security Specialist (CKS)
Domain 4Objective 2
Detect Threats Within Physical Infrastructure, Apps, Networks, Data, Users and Workloads CKS Practice Questions (Page 6)
Part of the Supply Chain Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
7concepts
20%of the exam
Questions 26–30
- 26
What is the primary purpose of threat detection in a comprehensive security strategy?
Select an answer first - 27
Which user behavior is a common indicator of a potential insider threat?
Select an answer first - 28
A security engineer is investigating a compromised container. The container was running a legitimate application, but it has been observed executing commands that are not part of the application's normal behavior. The engineer wants to determine if this is a malware infection or a misconfiguration. Which approach should they take?
Select an answer first - 29
A company has a multi-cluster Kubernetes environment. They have implemented threat detection tools, but the security team is overwhelmed by alerts. They want to prioritize alerts that indicate a real threat. Which approach should they take to improve the effectiveness of their threat detection?
Select an answer first - 30
Which activity is an example of application-level threat detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.