Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Certified Kubernetes Security Specialist (CKS)

Domain 2Objective 2

Understand Your Supply Chain (e.g. SBOM, CI/CD, Artifact Repositories) CKS Practice Questions (Page 3)

Part of the Minimize Microservice Vulnerabilities domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
7concepts
20%of the exam

Questions 11–15

  1. 11application · medium

    Your organization wants to enforce that only container images with verifiable provenance from your internal CI/CD pipeline can be deployed to production. You have implemented image signing. What additional control is necessary to enforce this policy at deployment time?

    Select an answer first
  2. 12expert · hard

    Your organization's CI/CD pipeline uses a base image from a public registry. An attacker compromises the public registry and replaces the base image with a malicious one. Your pipeline does not verify the base image's integrity. What is the most effective way to prevent this attack in the future?

    Select an answer first
  3. 13application · medium

    Your organization uses a central artifact repository (e.g., JFrog Artifactory or Sonatype Nexus) to store libraries and container images. You are concerned about a developer accidentally pushing a malicious package that could be used by other teams. Which control is most effective in preventing this?

    Select an answer first
  4. 14application · medium

    Your CI/CD pipeline builds and pushes container images to a private registry. You want to ensure that only images built from your trusted pipeline are deployed to production. Which combination of controls would best enforce this?

    Select an answer first
  5. 15application · medium

    During a routine audit, you discover that a popular open-source library used in your application was compromised by an attacker who injected malicious code into a published version. Your application uses a version range that includes the compromised version. Which immediate action is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.