
Certified Kubernetes Security Specialist (CKS)
Domain 4Objective 3
Investigate and Identify Phases of Attack and Bad Actors Within the Environment CKS Practice Questions (Page 3)
Part of the Supply Chain Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 16 practice questions to prepare you well beyond it. (estimate)
16questions here
4free pages
5concepts
20%of the exam
Questions 11–15
- 11
An attacker has successfully exploited a vulnerability in a web application running in a pod. They are now using that pod to scan the internal network for other services. Which phase of the attack lifecycle does this activity represent?
Select an answer first - 12
A security analyst is investigating a potential security incident in a Kubernetes cluster. They notice that a pod is making frequent DNS queries to a domain that is not associated with any known service. Which indicator of compromise (IoC) is this?
Select an answer first - 13
Which Kubernetes component is the primary entry point for all administrative and user requests to the cluster, making it a critical part of the attack surface?
Select an answer first - 14
During a forensic investigation of a Kubernetes security incident, which of the following is the most important first step to preserve evidence?
Select an answer first - 15
A security analyst notices that a previously legitimate container image is now behaving abnormally, making outbound connections to an unknown IP address. Which type of threat actor is most likely responsible for this behavior?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.