
Certified Kubernetes Security Specialist (CKS)
Domain 6Objective 3
Investigate and Identify Phases of Attack and Bad Actors Within the Environment CKS Practice Questions (Page 4)
Part of the Monitoring, Logging and Runtime Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)
18questions here
4free pages
5concepts
20%of the exam
Questions 16–18
- 16
During an incident investigation, you are examining a compromised pod. You have collected logs from the API server, kubelet, and the container itself. Which of the following is the most systematic approach to determine the sequence of events?
Select an answer first - 17
A cluster administrator discovers that a developer's service account token was used to create a deployment with a privileged container that mounts the host filesystem. The token was found in a public GitHub repository. Which type of threat actor is most likely responsible?
Select an answer first - 18
A security team notices unusual outbound traffic from a pod to a known malicious IP address. The pod is running a container image that was pulled from a public registry. The image has not been updated in months. Which threat actor is most likely responsible for the malicious activity?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CKS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.