
Certified Kubernetes Security Specialist (CKS)
Domain 1Objective 1
Secure Cluster Components CKS Practice Questions (Page 5)
Part of the Cluster Setup domain, which accounts for 15% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 2–3 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
7concepts
15%of the exam
Questions 21–25
- 21
Which kubelet configuration setting is recommended by the CIS Kubernetes Benchmark to secure kubelet API access?
Select an answer first - 22
Which authentication mode is recommended by the CIS Kubernetes Benchmark for the kube-apiserver?
Select an answer first - 23
How does the CIS Kubernetes Benchmark help in securing cluster components?
Select an answer first - 24
A cluster administrator is setting up a new control plane node. They have downloaded the `kube-controller-manager` binary and its checksum file. They want to verify the binary's authenticity, not just its integrity. What additional step should they take?
Select an answer first - 25
A cluster administrator is reviewing the CoreDNS deployment for security issues. They notice that CoreDNS is configured with `replicas: 2` and is using the `NodeLocal DNSCache` feature. The CIS benchmark recommends that CoreDNS run with the least privileges. Which configuration change should be made to align with this recommendation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CKS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.