CKS · domain
System Hardening
System Hardening covers reducing the attack surface of nodes and workloads: AppArmor and seccomp profiles, Linux capabilities, and Kubernetes Pod Security Admission. You are tested through hands-on tasks and multiple-choice items that require applying annotations, securityContext fields, and namespace labels correctly on a live cluster.
Focused practice
Practice System Hardening questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about System Hardening
Be able to edit a pod manifest to add AppArmor annotations, set seccompProfile, and drop capabilities, then verify with kubectl exec and node-level tools. The most important thing: confirm the profile is actually loaded and enforced, not just referenced.
Applying AppArmor profiles via container.apparmor.security.beta.kubernetes.io/<container> annotations and verifying enforcement
Configuring seccompProfile (RuntimeDefault, Localhost) in a pod's securityContext and troubleshooting profile loading
Dropping Linux capabilities such as NET_RAW with securityContext.capabilities.drop and assessing the impact
Enforcing pod security defaults across a namespace using Pod Security Admission labels and restricted/baseline policies
Watch out for
Common System Hardening exam traps
- ▸Assuming an AppArmor profile is enforced when the node has it in complain mode; complain mode only logs violations and does not block them.
- ▸Forgetting that seccomp and AppArmor annotations are per-container, not per-pod, so a wrong container name silently leaves the profile unapplied.
- ▸Believing NET_RAW is harmless; dropping it breaks tools like ping and raw-socket scanners, and some CNI or monitoring agents may rely on it.
Question index
All System Hardening questions (137)
Click any question to see the full explanation, or start a practice session above.
A security engineer wants to enforce that all containers in a namespace run without any unnecessary Linux capabilities, dropping all capabilities by default and only adding back what is needed. Which Pod Security Standard should be applied to that namespace using PodSecurity admission?
Medium2A security auditor recommends limiting the use of host namespaces in pods. Which THREE of the following fields, if set to true, expose the host namespace to a container?
Hard3You are managing a Kubernetes cluster that hosts multiple microservices. The cluster uses Kubernetes v1.25. Recently, a security audit identified that containers are running with the default seccomp profile (unconfined). The security team has requested that all containers use a seccomp profile that blocks unnecessary syscalls. You need to implement this cluster-wide without breaking existing applications. The audit also found that the kubelet's anonymous authentication is enabled, which should be disabled. Additionally, you need to ensure that the kubelet's NodeRestriction admission controller is enabled to limit what nodes can do. Which of the following is the most appropriate sequence of actions?
Medium4A security team is hardening a Kubernetes cluster. They need to ensure that all control plane components run with the least privilege. Which approach should they take?
Medium5Which TWO AppArmor modes are available? (Select 2)
Medium6A cluster administrator wants to enforce the Pod Security Standard 'restricted' at the namespace level. Which command applies the PodSecurity admission label to the 'prod' namespace?
Hard7A DevOps team wants to ensure that all container images are pulled from a trusted registry only. Which cluster-level configuration should be applied?
Easy8A container is running with the following securityContext: securityContext: capabilities: drop: ["ALL"] add: ["NET_BIND_SERVICE"] Which capabilities will the container have?
Medium9Which of the following is correct about dropping the 'NET_RAW' capability?
Medium10An administrator wants to use AppArmor to confine a container. They have loaded a profile named 'my-custom-profile' using apparmor_parser. Which annotation should be added to the pod to enforce this profile?
Hard11What is the purpose of the 'seccomp' feature in Kubernetes?
Easy12A pod is scheduled on a node that has AppArmor enabled, and the pod has the annotation 'container.apparmor.security.beta.kubernetes.io/nginx: localhost/deny-write'. The profile 'deny-write' is loaded. However, the nginx container is able to write to the filesystem. What is the most likely issue?
Medium13A node in your cluster is running unnecessary services that increase the attack surface. Which of the following is the BEST approach to reduce the attack surface on the node?
Medium14Match each etcd security configuration to its description.
Medium15You are tasked with reducing the attack surface on a Kubernetes node. Which of the following actions is LEAST effective for hardening the node itself?
Hard16A security policy requires that all containers in the 'staging' namespace drop all Linux capabilities and only add the necessary ones. Which pod security context configuration achieves this?
Medium17Which THREE of the following are recommended practices for securing container images in a Kubernetes environment?
Medium18A pod is using a custom seccomp profile stored at /var/lib/kubelet/seccomp/custom-profile.json. Which securityContext configuration correctly references this profile?
Hard19An admin wants to check which AppArmor profiles are loaded. Which command should they run?
Easy20A security team wants to enforce that no container in the 'restricted' namespace runs with added Linux capabilities beyond the default set (according to the restricted Pod Security Standard). Which PodSecurityConfiguration should be applied to the namespace?
Hard21Which THREE of the following are correct statements about seccomp in Kubernetes? (Select 3)
Hard22An administrator wants to enforce that all pods in a namespace use the restricted Pod Security Standard. Which of the following commands correctly enables this enforcement?
Medium23Which TWO of the following are valid methods to apply a seccomp profile to a container? (Select 2 correct answers)
Medium24A custom seccomp profile is created at /var/lib/kubelet/seccomp/custom-profile.json. Which YAML snippet applies this profile to a container?
Hard25A pod is configured with securityContext: { seccompProfile: { type: RuntimeDefault } }. Which of the following is true about this configuration?
Hard26A pod is created with the following security context: securityContext: seccompProfile: type: Localhost localhostProfile: profiles/audit.json Where must the 'audit.json' file be placed on the node?
Medium27Order the steps to configure and use Falco for runtime security in a Kubernetes cluster.
Medium28Which of the following is the correct command to load an AppArmor profile from a file named 'my-profile'?
Easy29A pod is running with AppArmor enabled using a profile named 'k8s-apparmor-profile'. You want to verify that the profile is loaded and set to enforce mode. Which command should you run on the node?
Medium30A pod with the following annotation is created: 'container.apparmor.security.beta.kubernetes.io/webserver: localhost/k8s-apparmor-profile'. However, the pod remains in 'Pending' state and the node logs show 'AppArmor not available'. What is the most likely cause?
Medium31A pod is running with securityContext.seccompProfile.type: Unconfined. Which statement is true?
Medium32An administrator wants to enforce a custom AppArmor profile named 'k8s-apparmor-example' on a pod. The profile has been loaded on the node. Which annotation should be added to the pod's metadata to apply this profile?
Medium33Which of the following commands shows all loaded AppArmor profiles?
Easy34Which THREE of the following are best practices for minimizing host access from containers to reduce the attack surface? (Select three.)
Hard35Which TWO of the following are effective methods to harden the kubelet against unauthorized access?
Hard36A cluster has enabled the NodeRestriction admission controller. A developer is trying to create a pod with hostNetwork: true but is getting an error. What is the most likely reason?
Hard37Which THREE of the following are best practices for reducing the attack surface of Kubernetes nodes? (Select three.)
Hard38A container needs to run with the NET_ADMIN capability to modify network settings. The cluster enforces the baseline Pod Security Standard. Which securityContext configurations are valid? (Select all that apply.)
Medium39What is the default seccomp profile applied when a pod's security context has 'seccompProfile.type: RuntimeDefault'?
Easy40A cluster uses PodSecurity admission. A namespace has the label 'pod-security.kubernetes.io/enforce: baseline'. A user creates a pod that runs a container with 'privileged: true'. What happens?
Hard41Which TWO of the following are valid AppArmor profile modes? (Select 2 correct answers)
Hard42Which TWO of the following are valid methods to apply a seccomp profile to a Kubernetes pod? (Select two.)
Medium43Which THREE of the following are restrictions enforced by the 'baseline' Pod Security Standard? (Select three.)
Medium44A cluster uses a custom mutating admission webhook that adds a sidecar container to all pods. After an upgrade, the webhook crashes and pods cannot be created. What is the best way to prevent this scenario in future?
Medium45Which TWO of the following are true about AppArmor profiles in Kubernetes?
Hard46A security auditor wants to ensure that no container in the cluster has the CAP_SYS_ADMIN capability. Which of the following is the most effective way to enforce this cluster-wide?
Hard47A pod runs with 'hostNetwork: true' and 'hostPID: true'. Which security concern is MOST directly increased?
Hard48Which annotation is used to apply an AppArmor profile to a pod?
Easy49Which Pod Security Standard level allows the use of hostNetwork, hostPID, and hostIPC?
Easy50Which TWO of the following are valid AppArmor profile modes?
Medium51What is the default seccomp profile for Kubernetes containers when no seccompProfile is specified?
Medium52Which of the following correctly adds the NET_ADMIN capability to a container in a Kubernetes pod?
Medium53You are a security engineer at a company running a Kubernetes cluster in production. The cluster uses containerd as the container runtime and has been configured with Node Authorizer and NodeRestriction admission controller. Recently, a security audit revealed that several pods running as root have been compromised via container escape vulnerabilities. The audit report recommends hardening the nodes to reduce the attack surface. Specifically, you need to ensure that even if an attacker gains root access inside a container, they cannot execute privileged operations on the host node, such as loading kernel modules, modifying host network settings, or accessing host devices. The cluster runs on Ubuntu 20.04 nodes with Linux kernel 5.4. You have access to modify node-level configurations but must minimize performance impact and avoid breaking existing workloads that rely on standard Linux capabilities. Which of the following actions would most effectively mitigate these risks?
Hard54Which THREE of the following actions help reduce the attack surface of containers? (Select 3 correct answers)
Medium55Which command loads an AppArmor profile from a file into the kernel?
Easy56A pod spec includes 'hostPID: true' and 'hostNetwork: true'. What security concern does this raise?
Medium57A Pod is being deployed with a securityContext that sets runAsUser: 1000 and runAsGroup: 3000. The container image's files are owned by root:root with permissions 755. The application needs to write to a directory /data that is mounted as an emptyDir volume. What will happen when the container attempts to write to /data?
Easy58A cluster has been compromised due to a container running with privileged escalation. The team wants to prevent any container from gaining new privileges. Which configuration should be applied?
Hard59A security engineer is hardening a cluster and wants to reduce the attack surface of Pods by restricting their access to host resources. The engineer is reviewing a Pod specification and plans to remove or disable settings that grant host-level access. Which two settings should the engineer remove or set to false to reduce the attack surface? (Choose two.)
Hard60Given the exhibit, what will happen when a user creates a pod with an image from an untrusted registry?
Hard61Which command is used to check whether AppArmor is enabled and which profiles are loaded on a Linux node?
Easy62Which tool is used to load AppArmor profiles on a node?
Easy63An administrator wants to drop all capabilities for a container and then add back only NET_BIND_SERVICE. Which securityContext configuration is correct?
Medium64What is the effect of setting 'hostPID: true' in a pod's spec?
Medium65A pod is configured with a custom seccomp profile stored at /var/lib/kubelet/seccomp/custom-profile.json. The pod manifest uses securityContext.seccompProfile with type: Localhost and localhostProfile: "custom-profile.json". The pod fails to start with an error 'seccomp profile not found'. What is the most likely cause?
Hard66Refer to the exhibit. A security engineer sees that podPidsLimit is set to -1. What security concern does this raise?
Easy67Which of the following is a valid way to check the status of AppArmor profiles on a node?
Easy68An administrator wants to enforce that no container in a specific namespace runs with the privileged security context. They decide to use Pod Security Standards. Which Pod Security Standard level should be applied to the namespace?
Medium69A container runs as non-root and needs to perform operations that require CAP_SYS_PTRACE. Which YAML snippet correctly adds only this capability while following the principle of least privilege?
Hard70Which of the following is NOT a valid seccomp profile type in Kubernetes?
Medium71Which TWO of the following are valid ways to reduce the attack surface of a Kubernetes node? (Select 2)
Medium72You are a platform engineer for a financial services company. Your Kubernetes cluster runs on bare-metal nodes with Ubuntu 20.04 and uses containerd as the container runtime. The cluster is in production with 50 worker nodes. A recent security scan shows that all nodes have the 'overlayfs' kernel module loaded, which is not required. The security policy requires minimal kernel modules. You need to disable the module without disrupting running containers. What should you do?
Easy73Which Pod Security Standard level allows the most relaxed security controls?
Easy74A container runs with the default seccomp profile but the application needs to make a specific syscall that is blocked. Which approach should be taken?
Medium75An administrator wants to run a container that requires the SYS_TIME capability. Which field should be used in the securityContext to add this capability?
Medium76An administrator needs to enforce the restricted Pod Security Standard on a namespace 'secure-ns'. Which kubectl command should they use?
Medium77A security admin wants to drop all Linux capabilities for a container and then add only CAP_NET_BIND_SERVICE. Which YAML snippet correctly achieves this?
Medium78Which THREE of the following are recommended practices for securing the etcd datastore?
Medium79You need to apply a seccomp profile to all containers in a pod. The profile is named 'custom-profile.json' and is stored on each node at /var/lib/kubelet/seccomp/. Complete the following YAML snippet: ```yaml apiVersion: v1 kind: Pod metadata: name: secure-pod spec: securityContext: seccompProfile: type: Localhost localhostProfile: ??? ``` What should replace ???
Medium80A pod in namespace 'secure' has the following securityContext: securityContext: runAsNonRoot: true runAsUser: 1000 capabilities: drop: ["ALL"] add: ["NET_BIND_SERVICE"] The pod fails to start. The namespace is enforced with the 'restricted' Pod Security Standard. What is the most likely reason?
Medium81A DevOps engineer wants to ensure that all pods in a namespace have seccomp set to RuntimeDefault unless explicitly overridden. Which approach should be used to enforce this?
Medium82A pod manifest is shown. What security issue remains in this configuration?
Medium83A pod is running with a custom seccomp profile located at /var/lib/kubelet/seccomp/my-profile.json. Which securityContext configuration correctly applies this profile?
Medium84Which of the following is the correct way to drop all Linux capabilities for a container?
Medium85Which command is used to load an AppArmor profile into the kernel?
Easy86An admin runs 'kubectl describe pod secure-pod' and sees 'seccompProfile: RuntimeDefault' under the container's security context. Which seccomp profile is being used?
Medium87Which annotation is used to apply an AppArmor profile to a pod in Kubernetes?
Easy88An administrator needs to apply a seccomp profile to a Pod. The profile is defined in a file named audit.json located on each node at /var/lib/kubelet/seccomp/profiles/audit.json. The cluster is running Kubernetes 1.25. Which seccomp type should be used in the Pod's securityContext to reference this profile?
Medium89A security auditor wants to verify that the AppArmor profile 'my-profile' is in enforce mode on a running container. Which command should they run inside the node?
Medium90Which annotation is used to apply an AppArmor profile named 'custom-profile' to a container named 'app' in a pod?
Easy91Which of the following is the correct way to apply an AppArmor profile named 'my-profile' to a pod using the annotation?
Medium92An administrator creates a custom seccomp profile and places it at /var/lib/kubelet/seccomp/myprofile.json. Which securityContext field is used to apply this profile to a container?
Medium93You have built a custom seccomp profile at /var/lib/kubelet/seccomp/audit.json. Which YAML snippet correctly applies this profile to a container?
Hard94Which TWO of the following are effective measures to harden the Kubernetes API server against unauthorized access?
Hard95An attacker exploited a container escape vulnerability. The team wants to mitigate such attacks by restricting containers from accessing the host's kernel capabilities. Which set of capabilities should be dropped from all containers?
Hard96Which THREE of the following are recommended measures to reduce the attack surface of Kubernetes nodes?
Hard97Which TWO of the following are valid modes for an AppArmor profile?
Easy98A Pod must be prevented from reading or writing to its container root filesystem. The application only writes to an emptyDir mount at /tmp. Which securityContext field should be set in the Pod specification to enforce this at the container level?
Medium99Which TWO of the following are valid Pod Security Standards levels?
Medium100To reduce the attack surface, a security best practice is to drop all capabilities from a container and add only those required. Which securityContext field is used to drop all capabilities?
Easy101An administrator wants to ensure that containers in a pod cannot run with any Linux capabilities except the minimal required for the container runtime. The pod is subject to the 'restricted' Pod Security Standard. Which capability configuration should be set in the pod's security context?
Hard102A security team wants to ensure that all containers in a pod run with only the minimum required Linux capabilities. Which of the following approaches is BEST?
Medium103Which TWO of the following are valid methods to apply a custom seccomp profile to a pod in Kubernetes?
Medium104Which of the following is NOT a recommended method to reduce the attack surface on Kubernetes nodes?
Medium105Which of the following host access settings should be disabled to reduce the attack surface of a container?
Easy106After deploying a pod with an AppArmor profile, the pod status shows 'ContainerCreating' for a long time and then fails. What is the most likely cause?
Hard107Which TWO of the following are valid AppArmor profile modes? (Select two.)
Medium108A security auditor reviews a Kubernetes cluster and finds that several nodes have container runtimes with default configurations. Which TWO of the following actions should be taken to harden the container runtime?
Medium109A pod has the following security context: capabilities: { drop: ['ALL'] } and privileged: false. The pod fails to start because it requires the ability to run iptables commands. Which of the following should be added to the pod's security context?
Medium110An administrator wants to reduce the attack surface of a Kubernetes node by disabling unnecessary system services. Which of the following services is considered unnecessary on a dedicated Kubernetes worker node and can be safely disabled?
Hard111A cluster administrator wants to apply a custom seccomp profile located at '/var/lib/kubelet/seccomp/audit.json' to a pod. Which YAML snippet correctly configures the pod's security context to use this profile?
Hard112Which Linux capability must be added to a container to allow it to change the system time (e.g., using the 'date' command)?
Easy113An administrator creates a custom seccomp profile and wants to apply it to a pod. The profile file is named 'audit.json' and is placed in the default seccomp directory on the node. Which securityContext field should be used?
Medium114Which of the following fields in a PodSecurityPolicy (or Pod Security Standards) prevents a container from running as root?
Easy115A custom seccomp profile is defined as follows: { "defaultAction": "SCMP_ACT_ALLOW", "architectures": ["SCMP_ARCH_X86_64"], "syscalls": [ { "names": ["mkdir", "chmod"], "action": "SCMP_ACT_ERRNO" } ] } The profile is placed at /var/lib/kubelet/seccomp/deny-mkdir.json. Which pod securityContext configuration correctly applies this profile?
Hard116An administrator wants to enforce the Pod Security Standard 'restricted' for all pods in the 'secure' namespace. Which kubectl command correctly enables the PodSecurity admission controller for that namespace?
Medium117A cluster administrator wants to enforce that all pods in the 'restricted' namespace use the Restricted Pod Security Standard. Which command achieves this?
Medium118During a security audit, it was found that some pods have access to the host network. How can an administrator restrict host network access for all pods in the cluster?
Medium119Which TWO of the following are valid Pod Security Standard levels? (Select 2)
Medium120A pod in the 'production' namespace is in a CrashLoopBackOff state. The pod has been running successfully for several days. You run 'kubectl describe pod app-pod -n production' and see the message: 'OOMKilled'. What is the MOST appropriate action to resolve this issue?
Medium121Which TWO of the following are valid approaches to restrict which nodes a pod can run on?
Hard122An administrator wants to restrict pods from running as root. Which admission controller should be enabled?
Easy123Which of the following host access settings should be avoided to minimize the attack surface from containers? (Select the setting that increases risk the most.)
Medium124You are creating a custom seccomp profile for a container that runs a binary requiring the 'write' syscall only. You place the profile JSON file at '/var/lib/kubelet/seccomp/profiles/write-only.json'. In the pod spec, which seccomp configuration correctly uses this profile?
Hard125A Kubernetes cluster uses containerd as the container runtime. The security team wants to restrict a specific container so it cannot create raw network packets. The container image runs as root and the Pod specification does not drop any capabilities. Which Linux capability should be dropped from the container's securityContext to prevent raw packet creation while still allowing binding to privileged ports?
Hard126An AppArmor profile is loaded in 'complain' mode. What happens when a pod with that profile attempts an action that violates the profile?
Hard127An administrator runs 'aa-status' on a node and sees a profile in 'complain' mode. What does this indicate?
Medium128Which THREE of the following are best practices for reducing the attack surface of a Kubernetes node?
Hard129Which of the following is the correct way to disable swap on a Kubernetes node to improve security?
Medium130Which of the following is the correct annotation to apply an AppArmor profile named 'my-profile' to a container named 'app' in a pod?
Easy131A cluster administrator wants to enforce Pod Security Standards at the namespace level using the built-in PodSecurity admission controller. The namespace 'test' should reject any pod that violates the 'baseline' level. Which command applies this correctly?
Medium132Which of the following seccomp profile types should be used to apply the container runtime's default seccomp profile?
Easy133Which THREE of the following are best practices for reducing the attack surface of Kubernetes nodes?
Medium134An administrator wants to prevent a container from accessing the host's network. Which pod security context field should be set to false?
Easy135A pod is scheduled on a node that has the AppArmor profile 'my-profile' loaded in complain mode. The pod annotation specifies 'localhost/my-profile' but the container is running without the profile being enforced. What is the most likely cause?
Hard136A cluster administrator has applied a PodSecurityPolicy (PSP) to restrict privileged containers. After upgrading to Kubernetes 1.25, they notice that PSPs are no longer working. What is the MOST likely reason?
Hard137Which command loads an AppArmor profile into the kernel?
EasyOther domains
All CKS exam domains
Frequently asked questions
- What does the System Hardening domain cover on the CKS exam?
- Be able to edit a pod manifest to add AppArmor annotations, set seccompProfile, and drop capabilities, then verify with kubectl exec and node-level tools. The most important thing: confirm the profile is actually loaded and enforced, not just referenced.
- How many questions are in this domain?
- This page lists all 137 System Hardening questions in the CKS question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only System Hardening questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.