
Certified Kubernetes Security Specialist (CKS)
Domain 1Objective 1
Secure Cluster Components CKS Practice Questions (Page 1)
Part of the Cluster Setup domain, which accounts for 15% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
7concepts
15%of the exam
Questions 1–5
- 1
A security audit of a cluster reveals that the kube-apiserver is configured with `--authorization-mode=AlwaysAllow`. The cluster is running in a production environment with multiple teams. Which configuration change should be made to enforce fine-grained access control?
Select an answer first - 2
A DevOps engineer is responsible for downloading and verifying Kubernetes binaries for a new cluster. They have downloaded the `kubelet` binary and its checksum file. They have verified the checksum, but they are concerned about a supply-chain attack where the checksum file itself could be compromised. What additional step should they take to mitigate this risk?
Select an answer first - 3
What is a key consideration when planning a Kubernetes upgrade?
Select an answer first - 4
A cluster is running Kubernetes v1.24.3. The security team has identified a critical vulnerability in the kube-apiserver that is patched in v1.24.7. The team needs to upgrade the cluster to a patched version with minimal downtime. Which upgrade strategy should they follow?
Select an answer first - 5
According to the CIS Kubernetes Benchmark, which of the following is a recommended security setting for etcd?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.