Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Certified Kubernetes Security Specialist (CKS)

Domain 5Objective 2

Using Least-Privilege Identity and Access Management CKS Practice Questions (Page 1)

Part of the System Hardening domain, which accounts for 10% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
8concepts
10%of the exam

Questions 1–5

  1. 1expert · hard

    Your cluster has audit logging enabled, but you notice that some API requests are not being logged. You need to ensure that all requests from service accounts are logged, especially those that could indicate privilege escalation. What should you do?

    Select an answer first
  2. 2foundation · easy

    In RBAC, what does the 'verb' field in a Role rule specify?

    Select an answer first
  3. 3foundation · easy

    Which field in a Role rule specifies the API group of the resource?

    Select an answer first
  4. 4foundation · easy

    What is the purpose of creating a dedicated service account for a pod?

    Select an answer first
  5. 5expert · hard

    You are investigating a potential security incident where a service account may have been used to delete pods in a namespace. You need to confirm whether the deletion was performed by that service account and identify the exact time. What should you examine?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.