Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Certified Kubernetes Security Specialist (CKS)

Domain 4Objective 1

Perform Behavioral Analytics to Detect Malicious Activities CKS Practice Questions (Page 4)

Part of the Supply Chain Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
6concepts
20%of the exam

Questions 16–20

  1. 16application · medium

    A Kubernetes cluster has audit logging enabled, but the security team notices that some API requests are not appearing in the audit logs. They suspect that the audit policy is too restrictive. Which audit policy level should be used to capture the request and response bodies for write operations, which are important for detecting malicious payloads?

    Select an answer first
  2. 17application · medium

    A security analyst is monitoring a Kubernetes cluster and notices that a pod is making DNS queries to a domain that has never been seen before in the cluster's DNS logs. The domain is not on any blocklist, and the pod's normal behavior involves only internal service discovery. Which threat detection technique is most directly applicable to flag this activity?

    Select an answer first
  3. 18application · medium

    A security analyst detects that a container in a production cluster is executing a known cryptocurrency miner, as identified by a Falco rule. The container is part of a Deployment with three replicas. Which immediate remediation action is most appropriate to contain the threat while minimizing impact on the application?

    Select an answer first
  4. 19foundation · easy

    What is the immediate first step when a container is confirmed to be running malicious code?

    Select an answer first
  5. 20application · medium

    A security team is using a SIEM to analyze Kubernetes audit logs. They want to detect a potential brute-force attack on the API server, where an attacker tries multiple passwords for a user account. Which audit log field is most useful for detecting this pattern?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.