Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Certified Kubernetes Security Specialist (CKS)

Domain 6Objective 3

Investigate and Identify Phases of Attack and Bad Actors Within the Environment CKS Practice Questions (Page 1)

Part of the Monitoring, Logging and Runtime Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)

18questions here
4free pages
5concepts
20%of the exam

Questions 1–5

  1. 1foundation · easy

    During a security review, you are examining the threat landscape of a Kubernetes environment. Which of the following is an example of a container-level vulnerability?

    Select an answer first
  2. 2application · medium

    While reviewing audit logs, you notice a series of failed `kubectl exec` attempts into a pod, followed by a successful `kubectl exec` that ran a command to download a binary from an external IP. Which attack phase does the successful `kubectl exec` most directly indicate?

    Select an answer first
  3. 3foundation · easy

    While reviewing container logs, you notice a series of failed login attempts to the Kubernetes API server from a single IP address, followed by a successful login and the execution of a command to create a new pod with a suspicious image. Which of the following is the most direct indicator of compromise (IoC) in this log sequence?

    Select an answer first
  4. 4expert · medium

    A security analyst is investigating a suspected attack. The audit logs show a `kubectl exec` into a pod, followed by the creation of a new pod with a hostPath mount, and then a series of `curl` commands to an external IP. The analyst needs to determine the attack phase to prioritize response. Which phase is the `kubectl exec` most directly indicating?

    Select an answer first
  5. 5foundation · easy

    A disgruntled employee with valid credentials to a Kubernetes cluster deletes critical deployments and modifies RBAC policies to lock out other administrators. Which type of threat actor does this scenario describe?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.