
Certified Kubernetes Security Specialist (CKS)
Domain 4Objective 4
Ensure Immutability of Containers at Runtime CKS Practice Questions (Page 2)
Part of the Supply Chain Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
5concepts
20%of the exam
Questions 6–10
- 6
Which container runtime configuration option makes the container's root filesystem read-only, preventing any writes to it during runtime?
Select an answer first - 7
What is the primary role of an admission controller like OPA/Gatekeeper in enforcing container immutability?
Select an answer first - 8
When a container's root filesystem is read-only, where should the application write temporary files that do not need to persist after the container terminates?
Select an answer first - 9
A security auditor needs to verify that a running container's root filesystem has not been modified since the image was pulled. The container is running with a read-only root filesystem. Which command should the auditor use to confirm immutability?
Select an answer first - 10
A DevOps engineer is updating a Deployment for a legacy application that writes to /var/lib/app. The security team mandates a read-only root filesystem. The application cannot be modified. What should the engineer do to make the Deployment compliant?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.