CKS › Minimize Microservice Vulnerabilities
This domain covers hardening the container layer itself: choosing and configuring sandboxed runtimes, keeping secrets out of environment variables, and applying pod-level security controls. On the CKS exam you are given a live cluster and must create RuntimeClass objects, wire them into pods, mount Secrets as volumes, and reason about gVisor and Kata Containers behavior under kubectl and YAML edits.
CKS Minimize Microservice Vulnerabilities — All 203 Questions
Every question in this domain with answers and detailed explanations.