
Certified Kubernetes Security Specialist (CKS)
Domain 1Objective 1
Secure Cluster Components CKS Practice Questions (Page 4)
Part of the Cluster Setup domain, which accounts for 15% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
7concepts
15%of the exam
Questions 16–20
- 16
According to the CIS Kubernetes Benchmark, which kubelet port should be disabled to prevent unauthenticated access?
Select an answer first - 17
Which kube-apiserver flag is used to enable encryption of secrets at rest, as recommended by the CIS Benchmark?
Select an answer first - 18
An administrator is hardening etcd for a multi-node cluster. They have enabled `--client-cert-auth=true` and configured TLS. They now want to restrict access to etcd to only the kube-apiserver. The cluster uses a network policy solution that supports both pod-level and node-level policies. What is the most effective way to restrict access?
Select an answer first - 19
Why is it important to upgrade Kubernetes components regularly?
Select an answer first - 20
Which etcd configuration flag is used to enable client certificate authentication as recommended by the CIS Benchmark?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.