
Certified Kubernetes Security Specialist (CKS)
Domain 2Objective 4
Perform Static Analysis of User Workloads and Container Images (e.g. Kubesec, KubeLinter) CKS Practice Questions (Page 1)
Part of the Minimize Microservice Vulnerabilities domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
6concepts
20%of the exam
Questions 1–5
- 1
In a CI/CD pipeline, where is the most appropriate stage to run a static analysis tool like KubeLinter on Kubernetes manifests?
Select an answer first - 2
A team uses KubeLinter to lint their Helm charts in CI. They want to ensure that no chart can deploy a workload with `privileged: true`. They have a `values.yaml` that conditionally sets `privileged` based on an environment variable. Which KubeLinter configuration is most appropriate?
Select an answer first - 3
When using Kubesec to analyze a Kubernetes deployment manifest, what does a higher risk score indicate?
Select an answer first - 4
What is the main benefit of integrating static analysis tools into a CI/CD pipeline?
Select an answer first - 5
What is the primary function of KubeLinter?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.