
Certified Kubernetes Security Specialist (CKS)
Domain 4Objective 5
Use Kubernetes Audit Logs to Monitor Access CKS Practice Questions (Page 3)
Part of the Supply Chain Security domain, which accounts for 20% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 15 practice questions to prepare you well beyond it. (estimate)
15questions here
3free pages
5concepts
20%of the exam
Questions 11–15
- 11
A security analyst is investigating a potential privilege escalation. They find an audit log entry showing a user 'dev-user' performing a 'create' operation on a 'role' in the 'default' namespace, with a response code of 201. What does this entry indicate?
Select an answer first - 12
A cluster administrator wants to audit all requests to the 'pods' resource in the 'kube-system' namespace, but only for 'create' and 'delete' verbs. They also want to audit all requests from the user 'auditor' at the Metadata level. Which audit policy rule should be placed first?
Select an answer first - 13
Which audit policy stage is triggered when the API server receives a request but before any processing occurs?
Select an answer first - 14
Which audit log field is most useful for correlating a suspicious request with its network origin?
Select an answer first - 15
Which API server flag controls the maximum number of days that old audit log files are retained?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CKS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.