
Certified Kubernetes Security Specialist (CKS)
Domain 4Objective 1
Perform Behavioral Analytics to Detect Malicious Activities CKS Practice Questions (Page 3)
Part of the Supply Chain Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
6concepts
20%of the exam
Questions 11–15
- 11
A Falco rule has fired, indicating that a container is attempting to mount the host filesystem. The container is running as root. What is the most immediate action to contain this threat?
Select an answer first - 12
Which flag is used to specify the file where Kubernetes audit logs are written?
Select an answer first - 13
Which pattern in audit logs is most indicative of a potential privilege escalation attempt?
Select an answer first - 14
A security team is investigating a series of suspicious API calls that appear to be using a legitimate service account token. The calls are creating pods with hostPath mounts and then deleting them quickly. The team suspects that the token has been compromised. Which combination of techniques would best confirm this suspicion?
Select an answer first - 15
A security team wants to implement behavioral analytics for their Kubernetes cluster. They have enabled audit logging and are collecting logs from the API server. They also have Falco running on each node. Which additional step is essential to effectively perform behavioral analytics?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.