
Certified Kubernetes Security Specialist (CKS)
Domain 4Objective 4
Ensure Immutability of Containers at Runtime CKS Practice Questions (Page 1)
Part of the Supply Chain Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
5concepts
20%of the exam
Questions 1–5
- 1
A security team wants to enforce container immutability but also needs to detect if a container's root filesystem is modified after startup. They plan to use OPA/Gatekeeper for admission control. What additional measure should they implement to detect runtime modifications?
Select an answer first - 2
Which Kubernetes API field enforces a read-only root filesystem for a container?
Select an answer first - 3
An organization uses OPA/Gatekeeper to enforce security policies. They want to ensure that no container in any namespace can mount a hostPath volume, as this could allow writes to the host filesystem, breaking immutability. Which Gatekeeper resource should be created?
Select an answer first - 4
A security analyst suspects that a running container has been compromised and its root filesystem modified. The container was started with a read-only root filesystem. Which tool or command can the analyst use to inspect the container's filesystem for changes?
Select an answer first - 5
A cluster runs workloads with a mix of containers that have read-only root filesystems and those that do not. The security team wants to enforce immutability for all new workloads without disrupting existing ones. Which approach achieves this with minimal risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.