Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Certified Kubernetes Security Specialist (CKS)

Domain 2Objective 3

Secure Your Supply Chain (permitted Registries, Sign and Validate Artifacts, Etc.) CKS Practice Questions (Page 3)

Part of the Minimize Microservice Vulnerabilities domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)

18questions here
4free pages
4concepts
20%of the exam

Questions 11–15

  1. 11expert · hard

    Your cluster runs a mix of workloads: some use images from the approved internal registry, and some use images from a legacy external registry that is still needed for one month. You must enforce that all images are signed, but the legacy registry does not support signing. You cannot change the legacy registry. What is the best approach?

    Select an answer first
  2. 12application · medium

    Your team signs container images with cosign using a private key. You want to ensure that only images signed by your team's key can run in the production cluster. Which admission controller setup should you implement?

    Select an answer first
  3. 13application · medium

    Your organization mandates that all container images must come from the internal registry at registry.corp.example.com. Developers sometimes push images to Docker Hub for testing. You need to enforce this policy cluster-wide. Which admission controller configuration should you use?

    Select an answer first
  4. 14application · medium

    Your team signs images with cosign and also scans them with Trivy in CI. You want to ensure that only signed and vulnerability-free images are deployed. Which admission controller configuration should you use?

    Select an answer first
  5. 15expert · hard

    Your cluster has multiple teams. Team A uses images from registry.corp.example.com and signs them with cosign. Team B uses images from the same registry but does not sign them. You need to enforce that all images in the cluster are signed, but you cannot break Team B's workloads. What is the best approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.