CKS Monitoring, Logging and Runtime Security Practice Question
An incident responder needs to isolate a compromised pod immediately without deleting it. Which action should they take?
⚠ Common exam trap
CKS often tests the distinction between 'isolate' and 'delete' — candidates instinctively pick deletion or label changes as the fastest containment, missing that NetworkPolicy default-deny is the only option that preserves the pod for forensics while cutting all traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply a NetworkPolicy that denies all traffic to and from the pod's labels
Applying a NetworkPolicy that denies all ingress and egress traffic to the pod's labels is the correct isolation action because it preserves the pod for forensic analysis while cutting off all network communication. Kubernetes NetworkPolicy operates at the pod-selector level, so a default-deny policy targeting the compromised pod's labels immediately blocks both inbound and outbound traffic without touching the pod's lifecycle. This satisfies the incident responder's requirement to isolate without deleting, keeping volatile memory and container state intact for investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Modify the pod's labels to prevent it from receiving traffic
Why it's wrong here
Changing pod labels is an unreliable isolation method because labels are metadata, not enforcement points. An attacker with network access can still communicate with the pod's IP unless a NetworkPolicy explicitly denies traffic, and controllers like Deployments may revert label changes. Additionally, relabeling could cause the pod to match a different, less restrictive NetworkPolicy, weakening security rather than containing the incident.
- ✗
Delete the pod to stop its activity
Why it's wrong here
Deleting the compromised pod terminates the running process, but it permanently destroys volatile forensic evidence such as memory contents, open network connections, and filesystem state. If the pod is managed by a ReplicaSet or Deployment, it will be immediately replaced, likely with the same labels and potentially the same vulnerability. Proper containment should preserve the pod for data collection while applying network-level isolation.
- ✓
Apply a NetworkPolicy that denies all traffic to and from the pod's labels
Why this is correct
Applying a NetworkPolicy that selects the compromised pod's labels and declares policyTypes: [Ingress, Egress] with no ingress or egress rules establishes an immediate default-deny boundary. The CNI enforces this at the data path, blocking all existing and new connections while leaving the pod and its logs, memory, and filesystem untouched for forensic analysis. This is the correct incident response because it contains the blast radius without destroying evidence.
- ✗
Scale down the deployment to zero replicas
Why it's wrong here
Scaling a Deployment to zero replicas forces the ReplicaSet controller to delete the pod, discarding all runtime evidence and any in-memory attack artifacts. The action is too broad—it may affect other healthy replicas and does not isolate the specific compromised instance; also, if the pod was created outside a Deployment's control, the action has no effect. Containment should target only the compromised pod via NetworkPolicy, not the entire workload.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.