
Certified Kubernetes Security Specialist (CKS)
Domain 6Objective 1
Perform Behavioral Analytics to Detect Malicious Activities CKS Practice Questions (Page 1)
Part of the Monitoring, Logging and Runtime Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
7concepts
20%of the exam
Questions 1–5
- 1
Which Falco rule condition would detect a shell being spawned inside a container?
Select an answer first - 2
A security analyst is reviewing Kubernetes audit logs and notices a series of requests from a user to list pods in the 'kube-system' namespace, each returning a 403 Forbidden. The requests occur every 5 minutes for an hour. Which conclusion is most likely?
Select an answer first - 3
A security analyst is configuring Falco to monitor both system calls and Kubernetes audit logs. They want to ensure that Falco processes events from both sources. Which configuration is required?
Select an answer first - 4
A company is deploying Falco in a Kubernetes cluster and wants to ensure that alerts are sent to a Slack channel. They have configured the Slack webhook in falco.yaml. Which additional configuration is necessary for Falco to load the custom rules they have written?
Select an answer first - 5
Which of the following activities would be considered a privilege escalation attempt that Falco can detect?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.