CNCF Certified Kubernetes Security Specialist (CKS) - 340 Questions
Practice exam for the Certified Kubernetes Security Specialist (CKS). Covers Cluster Setup, Cluster Hardening, System Hardening, Microservice Vulnerabilities, Supply Chain Security, and Runtime Security.
Premium Content
This exam is exclusive to Premium users. Upgrade to get unlimited access!
Become Premium👁️ Free Preview (5 of 340 questions)
1. A security engineer needs to ensure that all pods in the 'payments' namespace cannot receive any inbound traffic from pods in any other namespace. Which NetworkPolicy configuration achieves this?
2. A Kubernetes cluster administrator needs to allow only the 'monitoring' namespace to send traffic to pods labeled 'app=api' in the 'production' namespace on port 8080. All other ingress to these pods must be denied. Which NetworkPolicy achieves this?
3. A CKS candidate is reviewing a cluster's kube-apiserver configuration and finds the flag `--anonymous-auth=true`. What is the security risk of this setting and how should it be remediated?
4. During a CIS benchmark scan, a finding reports that the kube-apiserver is using `--authorization-mode=AlwaysAllow`. A security engineer must fix this. Which configuration correctly applies principle of least privilege authorization?
5. A security team is hardening a Kubernetes cluster according to the CIS Benchmark. They need to configure the kube-apiserver to use only strong TLS cipher suites. Which flag and value should be applied?
Want to test yourself for real?
Create a free account and run our exam simulation engine.
- Simulation engine
- Up to 10 questions per attempt
- Score & basic stats
- All 340 questions
- Detailed explanations
- Smart Practice + Focus Mode
Information
Tags
Related Exams
Microsoft Azure Security Technologies (AZ-500) - 340 Questions
340 questions · 0 attempts
Microsoft Cybersecurity Architect (SC-100) - 340 Questions
340 questions · 0 attempts
Microsoft Identity and Access Administrator (SC-300) - 340 Questions
340 questions · 0 attempts
AWS Certified Security Specialty (SCS-C03) - 340 Questions
340 questions · 0 attempts