CKS System Hardening Practice Question
An administrator wants to reduce the attack surface of a Kubernetes node by disabling unnecessary system services. Which of the following services is considered unnecessary on a dedicated Kubernetes worker node and can be safely disabled?
⚠ Common exam trap
Many exam-takers think sshd is unnecessary because Kubernetes nodes are managed via kubectl, but in practice, SSH access is critical for node-level troubleshooting, kernel updates, and emergency recovery, making it a required service unless a secure alternative like a serial console is in place.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cups
(cups) is correct because CUPS (Common Unix Printing System) is a print service that is unnecessary on a dedicated Kubernetes worker node, which does not require printing capabilities. Disabling it reduces the attack surface by removing a potential vector for privilege escalation or remote exploitation, as CUPS historically has had vulnerabilities like CVE-2024-35235. On a worker node, only essential services for container runtime, orchestration, and system management should run.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
containerd
Why it's wrong here
containerd is the container runtime interface (CRI) implementation that kubelet uses to pull images, create sandboxes, and manage container lifecycles. Without containerd, the node simply cannot run any pods, because there is no other daemon in the standard stack that can execute containers. Disabling it would immediately break the node's ability to host workload, which increases risk rather than reducing the cluster's real attack surface. It is therefore a wrong target for removal.
- ✗
sshd
Why it's wrong here
sshd provides encrypted remote access that cluster administrators commonly rely on for bootstrap, troubleshooting, kernel updates, and emergency recovery on worker nodes. While SSH is a legitimate network-facing service and should be hardened (key-based auth, fail2ban, restricted listeners), it is often a required operational tool rather than an unnecessary daemon. Removing it would force out-of-band management through the cloud console or IPMI, and many Kubernetes distributions still depend on SSH for node maintenance. It is not a safe first candidate for attack-surface reduction.
- ✓
cups
Why this is correct
CUPS (Common Unix Printing System) is a printing subsystem with a network-exposed daemon, cupsd, that implements IPP and legacy printing protocols. Kubernetes worker nodes do not need to act as print servers, and CUPS has historically had shell-injection and remote code execution vulnerabilities. Disabling or uninstalling CUPS eliminates a non-operational, network-listening service, directly reducing the node's attack surface. This makes it the correct service to remove.
- ✗
kubelet
Why it's wrong here
kubelet is the primary node agent that registers the node with the API server, executes PodSpecs, reports node and pod status, and interacts with containerd through the CRI. Without a functioning kubelet, the control plane cannot schedule workloads to that node and the node becomes effectively dead for Kubernetes purposes. Though kubelet is a large, attack-relevant component, it is absolutely essential for cluster operations and cannot be disabled. Removing it would be catastrophic, so it is a wrong choice.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.