
Certified Kubernetes Security Specialist (CKS)
Domain 6Objective 1
Perform Behavioral Analytics to Detect Malicious Activities CKS Practice Questions (Page 6)
Part of the Monitoring, Logging and Runtime Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
7concepts
20%of the exam
Questions 26–29
- 26
In a Falco rule, which component defines the reusable set of values that can be referenced in a condition?
Select an answer first - 27
Falco has detected a container that is writing to a suspicious file in /tmp and then executing a binary from the same directory. The security team wants to automate a response to stop this activity. Which action should they configure?
Select an answer first - 28
A security engineer is deploying Falco in a Kubernetes cluster and needs to detect when a container attempts to write to a file in /etc that is not a known package manager file. They want to minimize false positives from legitimate system updates. Which Falco rule construct should they use to define the set of allowed files?
Select an answer first - 29
A security analyst is investigating a potential data exfiltration. They have Falco configured to capture system calls and Kubernetes audit logs. Which event source would provide information about a user creating a pod with a hostPath volume?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CKS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.