Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Certified Kubernetes Security Specialist (CKS)

Domain 5Objective 2

Using Least-Privilege Identity and Access Management CKS Practice Questions (Page 2)

Part of the System Hardening domain, which accounts for 10% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
8concepts
10%of the exam

Questions 6–10

  1. 6application · medium

    A developer requests access to create pods in the 'dev' namespace. You create a RoleBinding that grants 'edit' access to the developer in that namespace. Later, you discover the developer can create RoleBindings in the 'dev' namespace. What is the likely cause?

    Select an answer first
  2. 7application · medium

    A pod needs to access the Kubernetes API to list pods in its own namespace. You want to grant this access without giving the pod any permissions outside that namespace. What should you do?

    Select an answer first
  3. 8foundation · easy

    What is the core purpose of the principle of least privilege in a Kubernetes cluster?

    Select an answer first
  4. 9foundation · easy

    How does namespace design help with least-privilege access?

    Select an answer first
  5. 10application · medium

    A DevOps team deploys a CronJob that needs to list and get Secrets in the 'prod' namespace. The team currently uses the default service account for the CronJob. You must ensure the job runs with minimal permissions. What should you do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.