
Certified Kubernetes Security Specialist (CKS)
Domain 5Objective 1
Minimize Host OS Footprint (reduce Attack Surface) CKS Practice Questions (Page 4)
Part of the System Hardening domain, which accounts for 10% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
7concepts
10%of the exam
Questions 16–20
- 16
Which of the following is a primary method to identify unnecessary packages installed on a host OS?
Select an answer first - 17
A security scan of a Kubernetes node reveals that the installed version of OpenSSL has a known vulnerability. The node is running a production workload and cannot be rebooted immediately. What should you do to mitigate the risk while planning the patch?
Select an answer first - 18
Which kernel parameter setting helps mitigate IP spoofing attacks?
Select an answer first - 19
A Kubernetes node is running an older version of the Linux kernel that has a known vulnerability. The node is part of a cluster that cannot be rebooted during business hours. The security team wants to mitigate the risk while planning the patch. What is the best approach?
Select an answer first - 20
A security audit of a Kubernetes node shows that the `cups` service is running and listening on port 631, but the node is a dedicated worker node with no printing needs. The team wants to reduce the attack surface. What should you do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.