Use kubectl auth can-i, RBAC RoleBindings, and kubelet --anonymous-auth=false to lock down API and node access. Get RBAC least privilege right, then upgrade control plane components with kubeadm upgrade.
Start practicing
Cluster Hardening — choose a session length
Free · No account required
Domain overview
Cluster Hardening covers the controls that keep a Kubernetes cluster's own components and API surface resistant to compromise. For the CKS exam you work hands-on inside a live cluster: restricting API access, tightening RBAC, protecting kubelet endpoints, and upgrading components safely. Tasks are performance-based, so you must know the exact kubectl, kubeadm and systemd commands and apply them under time pressure.
Exam objectives
Minimising RBAC permissions by removing wildcards, cluster-admin bindings and unnecessary default ServiceAccount rights
Securing the kubelet API with authentication, authorization and read-only port disabled via kubelet config
Restricting API server access using anonymous-auth, authorization modes and network exposure controls
Performing safe cluster upgrades with kubeadm upgrade plan, apply and node drain/uncordon sequencing
Leaving the kubelet read-only port 10255 open, or not disabling anonymous authentication on kubelet endpoints
Granting cluster-admin or wildcard verbs in Role/ClusterRole instead of least-privilege rules scoped to resources
Upgrading worker nodes before the control plane, or skipping kubeadm upgrade plan and etcd backups
Click any question to see the full explanation and answer options, or start a focused practice session above.
A security team wants to ensure that all pods in a namespace run with a restricted seccomp profile. Which Pod Security Standard admission controller mode should be used to enforce this without blocking necessary pods?
2A cluster uses RBAC and a ServiceAccount 'monitor' in namespace 'observability'. The account needs to list pods in all namespaces. Which ClusterRole and binding should be created?
3An administrator wants to prevent pods from running as root. Which SecurityContext field should be set at the pod level?
4A company uses kube-bench to scan their cluster. The report shows a warning: 'Ensure that the --authorization-mode argument is set to Node,RBAC'. What is the best way to fix this?
5A pod is failing to start with: 'Error: container has runAsNonRoot and image will run as root'. The pod spec sets securityContext.runAsNonRoot: true. The container image is 'nginx:latest' which runs as root. Which change allows the pod to run while maintaining security?
6Which Kubernetes resource should be used to restrict egress traffic from pods?
7A developer created a ClusterRole 'pod-reader' with rules to get, list, and watch pods, and bound it to a user. The user reports they cannot list pods in namespace 'test', although the same commands work in the 'default' namespace. What is the most likely cause?
8A cluster has a PodSecurityPolicy that requires 'RunAsAny' for the user. An administrator wants to enforce that all pods in namespace 'production' must run with a specific seccomp profile. Which approach is recommended given PSP is deprecated?
9Which TWO of the following are valid ways to restrict access to the Kubernetes API server?
10Which THREE of the following are required to secure etcd in a Kubernetes cluster?
11Which TWO of the following are best practices for securing container images?
12Which THREE of the following are valid methods to enforce pod security standards in a Kubernetes cluster?
13You are the security engineer for a multi-tenant Kubernetes cluster. The cluster uses kubeadm and runs Kubernetes v1.24. Each tenant has a dedicated namespace. A new tenant, 'acme-corp', requires that all pods in their namespace run with a read-only root filesystem and must not be able to escalate privileges. They also need to run a legacy container that must listen on a port below 1024. The cluster currently uses PodSecurityPolicy (PSP) but is planning to migrate to Pod Security Admission (PSA). The legacy container needs to run as non-root with the NET_BIND_SERVICE capability to bind to port 80. You need to configure security policies for the 'acme-corp' namespace without affecting other tenants. Which approach best meets these requirements while following Kubernetes best practices?
14Arrange the steps to enable and configure audit logging in Kubernetes.
15Match each Kubernetes security tool or feature to its purpose.
16A security team is hardening a cluster where the kube-apiserver is started with the flag --authorization-mode=Node,RBAC. A penetration test reveals that kubelet authentication is using anonymous requests and the webhook authorizer is not enabled. To ensure that kubelet API requests are authenticated and authorized, which combination of kubelet configuration changes should be applied?
17A Kubernetes administrator is reviewing the cluster's RBAC configuration and notices that a ClusterRoleBinding grants the cluster-admin role to the system:anonymous user. What is the most immediate and appropriate action to harden the cluster?
18You are hardening a kubeadm-managed cluster running Kubernetes v1.28. The kubelet's read-only port (10255) is still listening on every node, exposing pod and node metadata without authentication. You must disable it across the cluster. Which action is correct?
19A security review flags that developers can create pods that mount the host's /etc directory. You need to block hostPath volumes cluster-wide without breaking existing workloads that use the CSI driver for persistent storage. Which control is appropriate?
20An operator must upgrade a kubeadm cluster and wants to verify that the new control plane binaries are authentic before installing them. The team already has the Kubernetes release signing key. Which step confirms the integrity and origin of the downloaded binary?
Use kubectl auth can-i, RBAC RoleBindings, and kubelet --anonymous-auth=false to lock down API and node access. Get RBAC least privilege right, then upgrade control plane components with kubeadm upgrade.
The Courseiva CKS question bank contains 20 questions in the Cluster Hardening domain, covering the 15% of the exam attributed to this domain in the official CNCF blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Cluster Hardening domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included