Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Certified Kubernetes Security Specialist (CKS)

Domain 4Objective 4

Ensure Immutability of Containers at Runtime CKS Practice Questions (Page 4)

Part of the Supply Chain Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
5concepts
20%of the exam

Questions 16–20

  1. 16application · easy

    A security engineer is configuring a container runtime to ensure that containers cannot modify their root filesystem. Which runtime configuration achieves this goal?

    Select an answer first
  2. 17application · easy

    A container running with a read-only root filesystem needs to write temporary cache files. The cache must be cleared when the Pod restarts. Which volume type should be used?

    Select an answer first
  3. 18foundation · medium

    What is the primary purpose of configuring a container runtime to use a read-only root filesystem?

    Select an answer first
  4. 19application · medium

    A platform team wants to enforce that all new Pods in the production namespace have a read-only root filesystem. Developers sometimes forget to set this in their Pod specs. Which admission control approach should be used to enforce this policy automatically?

    Select an answer first
  5. 20expert · hard

    An organization uses OPA/Gatekeeper to enforce immutability. They want to allow a specific namespace (legacy-apps) to run containers without a read-only root filesystem, while enforcing it everywhere else. Which Gatekeeper configuration achieves this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.