CKSCertified Kubernetes Security Specialist

Practice Exam 1

5 of this form’s 15 questions, drawn from across its domains, free. The explanation on every one of them is free too, at every tier, and always will be.

  1. Question 1 of 5

    Kubelet configuration hardeningCluster Setup

    A cluster administrator wants every call reaching the kubelet API to be checked against cluster policy held by the API server. Which authorization mode is already in force?

  2. Question 2 of 5

    API server authorization chainCluster Hardening

    An administrator configures three authorization modules on the API server, and the second one denies a request outright. What follows that verdict?

  3. Question 3 of 5

    Projected volumes and service account tokensMinimize Microservice Vulnerabilities

    An engineer tries to project a Secret held in a shared namespace into a Pod that runs elsewhere, and the volume never resolves. What rule applies to projected sources?

  4. Question 4 of 5

    Container image build hygieneSupply Chain Security

    A company must justify its base image choice to an auditor who asks which badge means the vendor checked that the content in the repository genuinely came from the named organization.

  5. Question 5 of 5

    Audit policy rules and levelsMonitoring, Logging and Runtime Security

    An analyst builds a detection that treats the first entry of sourceIPs in each audit event as the true origin of the request. What is wrong with that reading?

0 of 15 completed

0%

The other 10 questions are the rest of this form: same 120 minute clock, same 67 cut score, and the same explanation on every question, which is never behind the wall. Practice Exam 1 of 2 on CKS.

What this exam covers

  • Cluster Setup2 questions / 15% of the exam
  • Cluster Hardening2 questions / 15% of the exam
  • System Hardening2 questions / 10% of the exam
  • Minimize Microservice Vulnerabilities3 questions / 20% of the exam
  • Supply Chain Security3 questions / 20% of the exam
  • Monitoring, Logging and Runtime Security3 questions / 20% of the exam

Checking what you already have access to.

Every question is original, written from the published objectives. We never reproduce, paraphrase, or imitate real exam content, and neither should anything else you study from.