Apply NetworkPolicies, configure API server admission plugins, secure Ingress with TLS, and run kube-bench. The critical thing: verify your NetworkPolicy actually blocks traffic using kubectl exec between pods.
Start practicing
Cluster Setup — choose a session length
Free · No account required
Domain overview
Cluster Setup is 15% of the CKS exam and covers hardening the Kubernetes control plane and worker nodes. You will perform live tasks in a terminal: applying NetworkPolicies, configuring API server admission controls, securing Ingress, and running kube-bench or CIS benchmark checks. Expect hands-on editing of manifests and verifying behaviour with kubectl rather than multiple-choice recall.
Exam objectives
Creating NetworkPolicy objects to restrict pod ingress and egress by namespace, label, and port
Enabling and configuring admission controllers such as NodeRestriction and PodSecurity admission on the API server
Hardening Ingress with TLS, and restricting access using NetworkPolicy or Ingress annotations
Running CIS benchmark tooling like kube-bench and remediating control plane and kubelet findings
Writing a NetworkPolicy that selects pods but forgets a matching egress or ingress rule, leaving traffic default-allowed in the other direction
Editing API server flags in a static pod manifest but not restarting the kubelet or verifying the change took effect
Assuming a default-deny NetworkPolicy blocks all traffic cluster-wide, when it only affects pods selected in that namespace
Click any question to see the full explanation and answer options, or start a focused practice session above.
A team needs to set up a highly available Kubernetes control plane across three availability zones. What is the minimum number of etcd members required to achieve fault tolerance against one zone failure?
2A security audit reveals that the kube-apiserver is using the default insecure port 8080 on a production cluster. Which is the most secure and recommended remediation?
3A cluster is using kubeadm and the control plane components are running as static pods. Where are the static pod manifests for the API server located by default?
4A security team wants to ensure that all communication between the kubelet and the API server is encrypted. Which flag must be set on the kubelet to enforce this?
5Order the steps to rotate a Kubernetes API server certificate.
6Match each Kubernetes admission controller to its role in security.
7A platform team runs a multi-tenant cluster and wants to enforce that all newly created Pods in the 'payments' namespace must run as non-root and must drop all Linux capabilities. The team decides to use a Pod Security Admission (PSA) label on the namespace. Which label value should they apply to the namespace to enforce these restrictions while still allowing other namespaces to remain unrestricted?
8A cluster administrator wants to enforce that all newly created pods in the 'production' namespace run with a read-only root filesystem. The cluster uses Kubernetes 1.25+ and the Pod Security Admission controller is enabled with the baseline and restricted profiles. Which namespace label must be applied to enforce the restricted policy?
Apply NetworkPolicies, configure API server admission plugins, secure Ingress with TLS, and run kube-bench. The critical thing: verify your NetworkPolicy actually blocks traffic using kubectl exec between pods.
The Courseiva CKS question bank contains 8 questions in the Cluster Setup domain, covering the 15% of the exam attributed to this domain in the official CNCF blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Cluster Setup domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included