
Certified Kubernetes Security Specialist (CKS)
Domain 1Objective 1
Secure Cluster Components CKS Practice Questions (Page 3)
Part of the Cluster Setup domain, which accounts for 15% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
7concepts
15%of the exam
Questions 11–15
- 11
What is the primary purpose of the CIS Kubernetes Benchmark?
Select an answer first - 12
What is a recommended security practice for CoreDNS according to the CIS Kubernetes Benchmark?
Select an answer first - 13
What is the purpose of verifying the checksum of a Kubernetes binary before deployment?
Select an answer first - 14
A cluster is experiencing issues with the kubelet's authorization. The kubelet is configured with `--authorization-mode=Webhook`. The kube-apiserver is configured with `--authorization-mode=RBAC`. Some kubelet requests are being denied, and the administrator suspects a misconfiguration. What is the most likely cause of the kubelet's authorization failures?
Select an answer first - 15
A security auditor is reviewing a Kubernetes cluster against the CIS Kubernetes Benchmark. The auditor notes that the kube-apiserver is configured with `--etcd-certfile` and `--etcd-keyfile`, but the etcd server itself is listening on a plain HTTP endpoint. The auditor flags this as a critical finding. Which remediation should the team implement to address the root cause of this finding?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.