
Certified Kubernetes Security Specialist (CKS)
Domain 6Objective 3
Investigate and Identify Phases of Attack and Bad Actors Within the Environment CKS Practice Questions (Page 2)
Part of the Monitoring, Logging and Runtime Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)
18questions here
4free pages
5concepts
20%of the exam
Questions 6–10
- 6
During a security investigation, you notice that an attacker has established a persistent connection from a compromised container to an external server, and is sending periodic commands. Which phase of the cyber attack lifecycle does this activity represent?
Select an answer first - 7
A security analyst discovers that a Kubernetes cluster has been compromised by an attacker who exploited a misconfigured kubelet to gain access. The attacker's actions were primarily focused on stealing secrets and deploying cryptocurrency miners. Which type of threat actor is most likely responsible?
Select an answer first - 8
An incident responder is analyzing a compromised pod. The pod's logs show a series of `wget` commands downloading multiple binaries, followed by a cron job being created inside the container. Which attack phase does the cron job creation most directly indicate?
Select an answer first - 9
You are investigating a security incident in a Kubernetes cluster. You have identified that a pod was created with a malicious image, and you need to determine how the attacker gained access to the cluster. Which of the following investigation techniques would be most effective for this purpose?
Select an answer first - 10
An analyst observes unusual network traffic from a Kubernetes node to an external IP address that is not on any known threat intelligence list. The traffic pattern includes repeated scans of internal services. Which phase of the attack lifecycle is most likely being observed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.