
Certified Kubernetes Security Specialist (CKS)
Domain 4Objective 1
Perform Behavioral Analytics to Detect Malicious Activities CKS Practice Questions (Page 2)
Part of the Supply Chain Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
6concepts
20%of the exam
Questions 6–10
- 6
Which action is part of the mitigation phase after a security incident in Kubernetes?
Select an answer first - 7
Which data source is most commonly used as the foundation for behavioral analytics in a Kubernetes control plane?
Select an answer first - 8
A security analyst is investigating a potential compromise. The audit logs show that a service account 'deployer' created a new pod with a hostPath mount to /var/run/docker.sock. The pod then ran a command that created a new user on the host. The analyst needs to determine the scope of the compromise. Which sequence of actions is most appropriate?
Select an answer first - 9
What is the primary purpose of Falco in a Kubernetes environment?
Select an answer first - 10
Which technology does Falco commonly use to capture system calls in modern kernels?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.