Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Certified Kubernetes Security Specialist (CKS)

Domain 6Objective 3

Investigate and Identify Phases of Attack and Bad Actors Within the Environment CKS Practice Questions (Page 3)

Part of the Monitoring, Logging and Runtime Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)

18questions here
4free pages
5concepts
20%of the exam

Questions 11–15

  1. 11foundation · easy

    A security team is assessing the attack surface of their Kubernetes cluster. Which of the following is a cluster-level vulnerability that could be exploited by an attacker?

    Select an answer first
  2. 12application · medium

    During an incident investigation, you correlate audit logs showing a service account creating a pod with a hostPath volume, then a container in that pod accessing `/etc/kubernetes` and reading secrets. Which investigation technique is most effective to confirm the full attack timeline?

    Select an answer first
  3. 13application · medium

    During an incident, you have audit logs showing a pod was created with a hostPath mount, then a container in that pod accessed `/etc/shadow`. You also have kubelet logs showing the pod was scheduled on a specific node. Which investigation technique would best help you determine if the attacker accessed other nodes?

    Select an answer first
  4. 14application · medium

    A cluster uses a service account that has `cluster-admin` privileges. An attacker compromises a pod and uses the service account token to create a new pod with a privileged container. Which Kubernetes-specific attack surface is most directly exploited?

    Select an answer first
  5. 15foundation · easy

    A security analyst is reviewing network traffic and notices that a container is communicating with an external IP address on a non-standard port, and the traffic is encrypted. The container's legitimate function does not require external communication. Which of the following is the most likely indicator of compromise (IoC)?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.