
Certified Kubernetes Security Specialist (CKS)
Domain 4Objective 5
Use Kubernetes Audit Logs to Monitor Access CKS Practice Questions (Page 1)
Part of the Supply Chain Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 15 practice questions to prepare you well beyond it. (estimate)
15questions here
3free pages
5concepts
20%of the exam
Questions 1–5
- 1
Which field in an audit log entry indicates the action that was performed on the resource?
Select an answer first - 2
A security team is investigating a potential data exfiltration. They notice that a service account 'backup-agent' is frequently reading Secrets in the 'production' namespace from a pod running on node 'node-3'. The audit logs show that the requests are successful (200). However, the team also sees that the same service account is making requests to the Kubernetes API from an unexpected source IP that is not associated with any node in the cluster. What is the most likely security concern?
Select an answer first - 3
An administrator is enabling audit logging on a cluster and wants to ensure that the audit log file does not consume too much disk space. They set --audit-log-maxsize=100 (MB) and --audit-log-maxbackup=5. What is the maximum amount of disk space that the audit logs can consume?
Select an answer first - 4
What is the primary purpose of enabling Kubernetes audit logging?
Select an answer first - 5
A security analyst is reviewing audit logs and sees a request from user 'bob' to 'get' a Secret in the 'default' namespace. The response code is 403. What does this indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.