Courseiva

CKS Monitoring, Logging and Runtime Security Practice Question

An incident responder needs to isolate a compromised pod immediately without deleting it. Which action should they take?

⚠ Common exam trap

CKS often tests the distinction between 'isolate' and 'delete' — candidates instinctively pick deletion or label changes as the fastest containment, missing that NetworkPolicy default-deny is the only option that preserves the pod for forensics while cutting all traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply a NetworkPolicy that denies all traffic to and from the pod's labels

Applying a NetworkPolicy that denies all ingress and egress traffic to the pod's labels is the correct isolation action because it preserves the pod for forensic analysis while cutting off all network communication. Kubernetes NetworkPolicy operates at the pod-selector level, so a default-deny policy targeting the compromised pod's labels immediately blocks both inbound and outbound traffic without touching the pod's lifecycle. This satisfies the incident responder's requirement to isolate without deleting, keeping volatile memory and container state intact for investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the pod's labels to prevent it from receiving traffic

    Why it's wrong here

    Changing pod labels is an unreliable isolation method because labels are metadata, not enforcement points. An attacker with network access can still communicate with the pod's IP unless a NetworkPolicy explicitly denies traffic, and controllers like Deployments may revert label changes. Additionally, relabeling could cause the pod to match a different, less restrictive NetworkPolicy, weakening security rather than containing the incident.

  • ✗

    Delete the pod to stop its activity

    Why it's wrong here

    Deleting the compromised pod terminates the running process, but it permanently destroys volatile forensic evidence such as memory contents, open network connections, and filesystem state. If the pod is managed by a ReplicaSet or Deployment, it will be immediately replaced, likely with the same labels and potentially the same vulnerability. Proper containment should preserve the pod for data collection while applying network-level isolation.

  • ✓

    Apply a NetworkPolicy that denies all traffic to and from the pod's labels

    Why this is correct

    Applying a NetworkPolicy that selects the compromised pod's labels and declares policyTypes: [Ingress, Egress] with no ingress or egress rules establishes an immediate default-deny boundary. The CNI enforces this at the data path, blocking all existing and new connections while leaving the pod and its logs, memory, and filesystem untouched for forensic analysis. This is the correct incident response because it contains the blast radius without destroying evidence.

  • ✗

    Scale down the deployment to zero replicas

    Why it's wrong here

    Scaling a Deployment to zero replicas forces the ReplicaSet controller to delete the pod, discarding all runtime evidence and any in-memory attack artifacts. The action is too broad—it may affect other healthy replicas and does not isolate the specific compromised instance; also, if the pod was created outside a Deployment's control, the action has no effect. Containment should target only the compromised pod via NetworkPolicy, not the entire workload.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.