
Certified Kubernetes Security Specialist (CKS)
Domain 5Objective 2
Using Least-Privilege Identity and Access Management CKS Practice Questions (Page 4)
Part of the System Hardening domain, which accounts for 10% of the CKS exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
8concepts
10%of the exam
Questions 16–20
- 16
What is a best practice for designing namespaces to support least privilege?
Select an answer first - 17
A microservice needs to read and write ConfigMaps in its namespace, but only during initialization. After startup, it should not have any API access. You need to design a secure solution. What should you do?
Select an answer first - 18
Which audit log level records the request and response metadata but not the request or response body?
Select an answer first - 19
Your organization has a multi-tenant cluster where each tenant has its own namespace. You need to ensure that tenants cannot access or modify resources outside their namespace, including the ability to create RoleBindings that could escalate privileges. What is the most effective control?
Select an answer first - 20
A company runs multiple applications in a single cluster. Each application team should only be able to access its own namespace. You need to design an RBAC strategy that enforces this isolation. What should you do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKS” is a trademark of its owner, used for identification only.