Free practice test
CKSFree Certified Kubernetes Security Specialist practice test
10 original CKS questions, playable right now. No account, no card, no email gate. Every answer opens the full explanation: the concept, why the right option is right, and why each wrong option is wrong, cited to the authoritative documentation behind it.
Sample question 1 of 10
A team runs a sidecar that presents its projected token to an in-cluster service never named in the projection audience. How should that service treat the token?
Sample question 2 of 10
An analyst builds a detection that treats the first entry of sourceIPs in each audit event as the true origin of the request. What is wrong with that reading?
Sample question 3 of 10
A company must justify its base image choice to an auditor who asks which badge means the vendor checked that the content in the repository genuinely came from the named organization.
Sample question 4 of 10
An administrator configures three authorization modules on the API server, and the second one denies a request outright. What follows that verdict?
Sample question 5 of 10
A cluster administrator wants every call reaching the kubelet API to be checked against cluster policy held by the API server. Which authorization mode is already in force?
Sample question 6 of 10
A node keeps its profiles at /var/lib/kubelet/seccomp/profiles/audit.json, and an engineer wants one Pod to use that file. Which securityContext values does the Pod carry?
Sample question 7 of 10
An engineer tries to project a Secret held in a shared namespace into a Pod that runs elsewhere, and the volume never resolves. What rule applies to projected sources?
Sample question 8 of 10
A team needs the submitted object body captured in the audit trail for every write to ConfigMaps. Which level must the matching rule name, at minimum?
Sample question 9 of 10
You have a repository holding credentials and local notes that keep landing in the build context, and restructuring the tree is not an option. What keeps them out?
Sample question 10 of 10
A Role grants only the list verb on secrets in a namespace, and a teammate argues that withholding get keeps the values hidden. What does a list call return?
Full CKS question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
What this test covers
These 10 questions are drawn across the published exam blueprint rather than from one chapter: this set touches Minimize Microservice Vulnerabilities, Monitoring, Logging and Runtime Security, Supply Chain Security, Cluster Hardening, Cluster Setup, System Hardening. Every question is original, written from the official objectives, and verified against a cited vendor page before it serves. None are recalled exam content, which is why the explanations can cite their sources.
A 10-question sample tells you where you stand, not whether you are ready. The full experience is numbered practice exams: 15 questions apportioned to the official domain weightings, sat under the real 120-minute clock and scored against the published cut score.
Keep reading
CKS practice questions
Free sample questions with the full explanation on every answer.
CKS passing score
The exact cut score, what kind of number it is, and the retake terms.
How hard is CKS?
An honest difficulty read from the format, the clock and the weights.