
Certified Kubernetes Security Specialist (CKS)
Domain 1Objective 2
Network Security CKS Practice Questions (Page 2)
Part of the Cluster Setup domain, which accounts for 15% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
11concepts
15%of the exam
Questions 6–10
- 6
What is a key security measure for protecting the Kubernetes API server endpoint?
Select an answer first - 7
A security audit reveals that the Kubernetes API server is accessible from all pods in the cluster, which is a risk. The cluster uses a CNI that supports NetworkPolicies. You need to restrict pod access to the API server (which runs on the control plane nodes) to only specific pods that need it. What is the best approach?
Select an answer first - 8
A cluster uses Cilium as the CNI. The security team wants to enable transparent encryption for all pod-to-pod traffic using IPsec. What is the first step to enable this in Cilium?
Select an answer first - 9
Which field in a NetworkPolicy spec defines the pods to which the policy applies?
Select an answer first - 10
What is the primary purpose of a Kubernetes NetworkPolicy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.