Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Certified Kubernetes Security Specialist (CKS)

Domain 1Objective 1

Secure Cluster Components CKS Practice Questions (Page 4)

Part of the Cluster Setup domain, which accounts for 15% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
7concepts
15%of the exam

Questions 16–20

  1. 16foundation · easy

    According to the CIS Kubernetes Benchmark, which kubelet port should be disabled to prevent unauthenticated access?

    Select an answer first
  2. 17foundation · easy

    Which kube-apiserver flag is used to enable encryption of secrets at rest, as recommended by the CIS Benchmark?

    Select an answer first
  3. 18expert · hard

    An administrator is hardening etcd for a multi-node cluster. They have enabled `--client-cert-auth=true` and configured TLS. They now want to restrict access to etcd to only the kube-apiserver. The cluster uses a network policy solution that supports both pod-level and node-level policies. What is the most effective way to restrict access?

    Select an answer first
  4. 19foundation · easy

    Why is it important to upgrade Kubernetes components regularly?

    Select an answer first
  5. 20foundation · easy

    Which etcd configuration flag is used to enable client certificate authentication as recommended by the CIS Benchmark?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.