Courseiva

CKS · domain

System Hardening

System Hardening covers reducing the attack surface of nodes and workloads: AppArmor and seccomp profiles, Linux capabilities, and Kubernetes Pod Security Admission. You are tested through hands-on tasks and multiple-choice items that require applying annotations, securityContext fields, and namespace labels correctly on a live cluster.

137 questions29 easy68 medium40 hard

Focused practice

Practice System Hardening questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about System Hardening

Be able to edit a pod manifest to add AppArmor annotations, set seccompProfile, and drop capabilities, then verify with kubectl exec and node-level tools. The most important thing: confirm the profile is actually loaded and enforced, not just referenced.

Applying AppArmor profiles via container.apparmor.security.beta.kubernetes.io/<container> annotations and verifying enforcement

Configuring seccompProfile (RuntimeDefault, Localhost) in a pod's securityContext and troubleshooting profile loading

Dropping Linux capabilities such as NET_RAW with securityContext.capabilities.drop and assessing the impact

Enforcing pod security defaults across a namespace using Pod Security Admission labels and restricted/baseline policies

Watch out for

Common System Hardening exam traps

  • ▸Assuming an AppArmor profile is enforced when the node has it in complain mode; complain mode only logs violations and does not block them.
  • ▸Forgetting that seccomp and AppArmor annotations are per-container, not per-pod, so a wrong container name silently leaves the profile unapplied.
  • ▸Believing NET_RAW is harmless; dropping it breaks tools like ping and raw-socket scanners, and some CNI or monitoring agents may rely on it.

Question index

All System Hardening questions (137)

Click any question to see the full explanation, or start a practice session above.

1

A security engineer wants to enforce that all containers in a namespace run without any unnecessary Linux capabilities, dropping all capabilities by default and only adding back what is needed. Which Pod Security Standard should be applied to that namespace using PodSecurity admission?

Medium
2

A security auditor recommends limiting the use of host namespaces in pods. Which THREE of the following fields, if set to true, expose the host namespace to a container?

Hard
3

You are managing a Kubernetes cluster that hosts multiple microservices. The cluster uses Kubernetes v1.25. Recently, a security audit identified that containers are running with the default seccomp profile (unconfined). The security team has requested that all containers use a seccomp profile that blocks unnecessary syscalls. You need to implement this cluster-wide without breaking existing applications. The audit also found that the kubelet's anonymous authentication is enabled, which should be disabled. Additionally, you need to ensure that the kubelet's NodeRestriction admission controller is enabled to limit what nodes can do. Which of the following is the most appropriate sequence of actions?

Medium
4

A security team is hardening a Kubernetes cluster. They need to ensure that all control plane components run with the least privilege. Which approach should they take?

Medium
5

Which TWO AppArmor modes are available? (Select 2)

Medium
6

A cluster administrator wants to enforce the Pod Security Standard 'restricted' at the namespace level. Which command applies the PodSecurity admission label to the 'prod' namespace?

Hard
7

A DevOps team wants to ensure that all container images are pulled from a trusted registry only. Which cluster-level configuration should be applied?

Easy
8

A container is running with the following securityContext: securityContext: capabilities: drop: ["ALL"] add: ["NET_BIND_SERVICE"] Which capabilities will the container have?

Medium
9

Which of the following is correct about dropping the 'NET_RAW' capability?

Medium
10

An administrator wants to use AppArmor to confine a container. They have loaded a profile named 'my-custom-profile' using apparmor_parser. Which annotation should be added to the pod to enforce this profile?

Hard
11

What is the purpose of the 'seccomp' feature in Kubernetes?

Easy
12

A pod is scheduled on a node that has AppArmor enabled, and the pod has the annotation 'container.apparmor.security.beta.kubernetes.io/nginx: localhost/deny-write'. The profile 'deny-write' is loaded. However, the nginx container is able to write to the filesystem. What is the most likely issue?

Medium
13

A node in your cluster is running unnecessary services that increase the attack surface. Which of the following is the BEST approach to reduce the attack surface on the node?

Medium
14

Match each etcd security configuration to its description.

Medium
15

You are tasked with reducing the attack surface on a Kubernetes node. Which of the following actions is LEAST effective for hardening the node itself?

Hard
16

A security policy requires that all containers in the 'staging' namespace drop all Linux capabilities and only add the necessary ones. Which pod security context configuration achieves this?

Medium
17

Which THREE of the following are recommended practices for securing container images in a Kubernetes environment?

Medium
18

A pod is using a custom seccomp profile stored at /var/lib/kubelet/seccomp/custom-profile.json. Which securityContext configuration correctly references this profile?

Hard
19

An admin wants to check which AppArmor profiles are loaded. Which command should they run?

Easy
20

A security team wants to enforce that no container in the 'restricted' namespace runs with added Linux capabilities beyond the default set (according to the restricted Pod Security Standard). Which PodSecurityConfiguration should be applied to the namespace?

Hard
21

Which THREE of the following are correct statements about seccomp in Kubernetes? (Select 3)

Hard
22

An administrator wants to enforce that all pods in a namespace use the restricted Pod Security Standard. Which of the following commands correctly enables this enforcement?

Medium
23

Which TWO of the following are valid methods to apply a seccomp profile to a container? (Select 2 correct answers)

Medium
24

A custom seccomp profile is created at /var/lib/kubelet/seccomp/custom-profile.json. Which YAML snippet applies this profile to a container?

Hard
25

A pod is configured with securityContext: { seccompProfile: { type: RuntimeDefault } }. Which of the following is true about this configuration?

Hard
26

A pod is created with the following security context: securityContext: seccompProfile: type: Localhost localhostProfile: profiles/audit.json Where must the 'audit.json' file be placed on the node?

Medium
27

Order the steps to configure and use Falco for runtime security in a Kubernetes cluster.

Medium
28

Which of the following is the correct command to load an AppArmor profile from a file named 'my-profile'?

Easy
29

A pod is running with AppArmor enabled using a profile named 'k8s-apparmor-profile'. You want to verify that the profile is loaded and set to enforce mode. Which command should you run on the node?

Medium
30

A pod with the following annotation is created: 'container.apparmor.security.beta.kubernetes.io/webserver: localhost/k8s-apparmor-profile'. However, the pod remains in 'Pending' state and the node logs show 'AppArmor not available'. What is the most likely cause?

Medium
31

A pod is running with securityContext.seccompProfile.type: Unconfined. Which statement is true?

Medium
32

An administrator wants to enforce a custom AppArmor profile named 'k8s-apparmor-example' on a pod. The profile has been loaded on the node. Which annotation should be added to the pod's metadata to apply this profile?

Medium
33

Which of the following commands shows all loaded AppArmor profiles?

Easy
34

Which THREE of the following are best practices for minimizing host access from containers to reduce the attack surface? (Select three.)

Hard
35

Which TWO of the following are effective methods to harden the kubelet against unauthorized access?

Hard
36

A cluster has enabled the NodeRestriction admission controller. A developer is trying to create a pod with hostNetwork: true but is getting an error. What is the most likely reason?

Hard
37

Which THREE of the following are best practices for reducing the attack surface of Kubernetes nodes? (Select three.)

Hard
38

A container needs to run with the NET_ADMIN capability to modify network settings. The cluster enforces the baseline Pod Security Standard. Which securityContext configurations are valid? (Select all that apply.)

Medium
39

What is the default seccomp profile applied when a pod's security context has 'seccompProfile.type: RuntimeDefault'?

Easy
40

A cluster uses PodSecurity admission. A namespace has the label 'pod-security.kubernetes.io/enforce: baseline'. A user creates a pod that runs a container with 'privileged: true'. What happens?

Hard
41

Which TWO of the following are valid AppArmor profile modes? (Select 2 correct answers)

Hard
42

Which TWO of the following are valid methods to apply a seccomp profile to a Kubernetes pod? (Select two.)

Medium
43

Which THREE of the following are restrictions enforced by the 'baseline' Pod Security Standard? (Select three.)

Medium
44

A cluster uses a custom mutating admission webhook that adds a sidecar container to all pods. After an upgrade, the webhook crashes and pods cannot be created. What is the best way to prevent this scenario in future?

Medium
45

Which TWO of the following are true about AppArmor profiles in Kubernetes?

Hard
46

A security auditor wants to ensure that no container in the cluster has the CAP_SYS_ADMIN capability. Which of the following is the most effective way to enforce this cluster-wide?

Hard
47

A pod runs with 'hostNetwork: true' and 'hostPID: true'. Which security concern is MOST directly increased?

Hard
48

Which annotation is used to apply an AppArmor profile to a pod?

Easy
49

Which Pod Security Standard level allows the use of hostNetwork, hostPID, and hostIPC?

Easy
50

Which TWO of the following are valid AppArmor profile modes?

Medium
51

What is the default seccomp profile for Kubernetes containers when no seccompProfile is specified?

Medium
52

Which of the following correctly adds the NET_ADMIN capability to a container in a Kubernetes pod?

Medium
53

You are a security engineer at a company running a Kubernetes cluster in production. The cluster uses containerd as the container runtime and has been configured with Node Authorizer and NodeRestriction admission controller. Recently, a security audit revealed that several pods running as root have been compromised via container escape vulnerabilities. The audit report recommends hardening the nodes to reduce the attack surface. Specifically, you need to ensure that even if an attacker gains root access inside a container, they cannot execute privileged operations on the host node, such as loading kernel modules, modifying host network settings, or accessing host devices. The cluster runs on Ubuntu 20.04 nodes with Linux kernel 5.4. You have access to modify node-level configurations but must minimize performance impact and avoid breaking existing workloads that rely on standard Linux capabilities. Which of the following actions would most effectively mitigate these risks?

Hard
54

Which THREE of the following actions help reduce the attack surface of containers? (Select 3 correct answers)

Medium
55

Which command loads an AppArmor profile from a file into the kernel?

Easy
56

A pod spec includes 'hostPID: true' and 'hostNetwork: true'. What security concern does this raise?

Medium
57

A Pod is being deployed with a securityContext that sets runAsUser: 1000 and runAsGroup: 3000. The container image's files are owned by root:root with permissions 755. The application needs to write to a directory /data that is mounted as an emptyDir volume. What will happen when the container attempts to write to /data?

Easy
58

A cluster has been compromised due to a container running with privileged escalation. The team wants to prevent any container from gaining new privileges. Which configuration should be applied?

Hard
59

A security engineer is hardening a cluster and wants to reduce the attack surface of Pods by restricting their access to host resources. The engineer is reviewing a Pod specification and plans to remove or disable settings that grant host-level access. Which two settings should the engineer remove or set to false to reduce the attack surface? (Choose two.)

Hard
60

Given the exhibit, what will happen when a user creates a pod with an image from an untrusted registry?

Hard
61

Which command is used to check whether AppArmor is enabled and which profiles are loaded on a Linux node?

Easy
62

Which tool is used to load AppArmor profiles on a node?

Easy
63

An administrator wants to drop all capabilities for a container and then add back only NET_BIND_SERVICE. Which securityContext configuration is correct?

Medium
64

What is the effect of setting 'hostPID: true' in a pod's spec?

Medium
65

A pod is configured with a custom seccomp profile stored at /var/lib/kubelet/seccomp/custom-profile.json. The pod manifest uses securityContext.seccompProfile with type: Localhost and localhostProfile: "custom-profile.json". The pod fails to start with an error 'seccomp profile not found'. What is the most likely cause?

Hard
66

Refer to the exhibit. A security engineer sees that podPidsLimit is set to -1. What security concern does this raise?

Easy
67

Which of the following is a valid way to check the status of AppArmor profiles on a node?

Easy
68

An administrator wants to enforce that no container in a specific namespace runs with the privileged security context. They decide to use Pod Security Standards. Which Pod Security Standard level should be applied to the namespace?

Medium
69

A container runs as non-root and needs to perform operations that require CAP_SYS_PTRACE. Which YAML snippet correctly adds only this capability while following the principle of least privilege?

Hard
70

Which of the following is NOT a valid seccomp profile type in Kubernetes?

Medium
71

Which TWO of the following are valid ways to reduce the attack surface of a Kubernetes node? (Select 2)

Medium
72

You are a platform engineer for a financial services company. Your Kubernetes cluster runs on bare-metal nodes with Ubuntu 20.04 and uses containerd as the container runtime. The cluster is in production with 50 worker nodes. A recent security scan shows that all nodes have the 'overlayfs' kernel module loaded, which is not required. The security policy requires minimal kernel modules. You need to disable the module without disrupting running containers. What should you do?

Easy
73

Which Pod Security Standard level allows the most relaxed security controls?

Easy
74

A container runs with the default seccomp profile but the application needs to make a specific syscall that is blocked. Which approach should be taken?

Medium
75

An administrator wants to run a container that requires the SYS_TIME capability. Which field should be used in the securityContext to add this capability?

Medium
76

An administrator needs to enforce the restricted Pod Security Standard on a namespace 'secure-ns'. Which kubectl command should they use?

Medium
77

A security admin wants to drop all Linux capabilities for a container and then add only CAP_NET_BIND_SERVICE. Which YAML snippet correctly achieves this?

Medium
78

Which THREE of the following are recommended practices for securing the etcd datastore?

Medium
79

You need to apply a seccomp profile to all containers in a pod. The profile is named 'custom-profile.json' and is stored on each node at /var/lib/kubelet/seccomp/. Complete the following YAML snippet: ```yaml apiVersion: v1 kind: Pod metadata: name: secure-pod spec: securityContext: seccompProfile: type: Localhost localhostProfile: ??? ``` What should replace ???

Medium
80

A pod in namespace 'secure' has the following securityContext: securityContext: runAsNonRoot: true runAsUser: 1000 capabilities: drop: ["ALL"] add: ["NET_BIND_SERVICE"] The pod fails to start. The namespace is enforced with the 'restricted' Pod Security Standard. What is the most likely reason?

Medium
81

A DevOps engineer wants to ensure that all pods in a namespace have seccomp set to RuntimeDefault unless explicitly overridden. Which approach should be used to enforce this?

Medium
82

A pod manifest is shown. What security issue remains in this configuration?

Medium
83

A pod is running with a custom seccomp profile located at /var/lib/kubelet/seccomp/my-profile.json. Which securityContext configuration correctly applies this profile?

Medium
84

Which of the following is the correct way to drop all Linux capabilities for a container?

Medium
85

Which command is used to load an AppArmor profile into the kernel?

Easy
86

An admin runs 'kubectl describe pod secure-pod' and sees 'seccompProfile: RuntimeDefault' under the container's security context. Which seccomp profile is being used?

Medium
87

Which annotation is used to apply an AppArmor profile to a pod in Kubernetes?

Easy
88

An administrator needs to apply a seccomp profile to a Pod. The profile is defined in a file named audit.json located on each node at /var/lib/kubelet/seccomp/profiles/audit.json. The cluster is running Kubernetes 1.25. Which seccomp type should be used in the Pod's securityContext to reference this profile?

Medium
89

A security auditor wants to verify that the AppArmor profile 'my-profile' is in enforce mode on a running container. Which command should they run inside the node?

Medium
90

Which annotation is used to apply an AppArmor profile named 'custom-profile' to a container named 'app' in a pod?

Easy
91

Which of the following is the correct way to apply an AppArmor profile named 'my-profile' to a pod using the annotation?

Medium
92

An administrator creates a custom seccomp profile and places it at /var/lib/kubelet/seccomp/myprofile.json. Which securityContext field is used to apply this profile to a container?

Medium
93

You have built a custom seccomp profile at /var/lib/kubelet/seccomp/audit.json. Which YAML snippet correctly applies this profile to a container?

Hard
94

Which TWO of the following are effective measures to harden the Kubernetes API server against unauthorized access?

Hard
95

An attacker exploited a container escape vulnerability. The team wants to mitigate such attacks by restricting containers from accessing the host's kernel capabilities. Which set of capabilities should be dropped from all containers?

Hard
96

Which THREE of the following are recommended measures to reduce the attack surface of Kubernetes nodes?

Hard
97

Which TWO of the following are valid modes for an AppArmor profile?

Easy
98

A Pod must be prevented from reading or writing to its container root filesystem. The application only writes to an emptyDir mount at /tmp. Which securityContext field should be set in the Pod specification to enforce this at the container level?

Medium
99

Which TWO of the following are valid Pod Security Standards levels?

Medium
100

To reduce the attack surface, a security best practice is to drop all capabilities from a container and add only those required. Which securityContext field is used to drop all capabilities?

Easy
101

An administrator wants to ensure that containers in a pod cannot run with any Linux capabilities except the minimal required for the container runtime. The pod is subject to the 'restricted' Pod Security Standard. Which capability configuration should be set in the pod's security context?

Hard
102

A security team wants to ensure that all containers in a pod run with only the minimum required Linux capabilities. Which of the following approaches is BEST?

Medium
103

Which TWO of the following are valid methods to apply a custom seccomp profile to a pod in Kubernetes?

Medium
104

Which of the following is NOT a recommended method to reduce the attack surface on Kubernetes nodes?

Medium
105

Which of the following host access settings should be disabled to reduce the attack surface of a container?

Easy
106

After deploying a pod with an AppArmor profile, the pod status shows 'ContainerCreating' for a long time and then fails. What is the most likely cause?

Hard
107

Which TWO of the following are valid AppArmor profile modes? (Select two.)

Medium
108

A security auditor reviews a Kubernetes cluster and finds that several nodes have container runtimes with default configurations. Which TWO of the following actions should be taken to harden the container runtime?

Medium
109

A pod has the following security context: capabilities: { drop: ['ALL'] } and privileged: false. The pod fails to start because it requires the ability to run iptables commands. Which of the following should be added to the pod's security context?

Medium
110

An administrator wants to reduce the attack surface of a Kubernetes node by disabling unnecessary system services. Which of the following services is considered unnecessary on a dedicated Kubernetes worker node and can be safely disabled?

Hard
111

A cluster administrator wants to apply a custom seccomp profile located at '/var/lib/kubelet/seccomp/audit.json' to a pod. Which YAML snippet correctly configures the pod's security context to use this profile?

Hard
112

Which Linux capability must be added to a container to allow it to change the system time (e.g., using the 'date' command)?

Easy
113

An administrator creates a custom seccomp profile and wants to apply it to a pod. The profile file is named 'audit.json' and is placed in the default seccomp directory on the node. Which securityContext field should be used?

Medium
114

Which of the following fields in a PodSecurityPolicy (or Pod Security Standards) prevents a container from running as root?

Easy
115

A custom seccomp profile is defined as follows: { "defaultAction": "SCMP_ACT_ALLOW", "architectures": ["SCMP_ARCH_X86_64"], "syscalls": [ { "names": ["mkdir", "chmod"], "action": "SCMP_ACT_ERRNO" } ] } The profile is placed at /var/lib/kubelet/seccomp/deny-mkdir.json. Which pod securityContext configuration correctly applies this profile?

Hard
116

An administrator wants to enforce the Pod Security Standard 'restricted' for all pods in the 'secure' namespace. Which kubectl command correctly enables the PodSecurity admission controller for that namespace?

Medium
117

A cluster administrator wants to enforce that all pods in the 'restricted' namespace use the Restricted Pod Security Standard. Which command achieves this?

Medium
118

During a security audit, it was found that some pods have access to the host network. How can an administrator restrict host network access for all pods in the cluster?

Medium
119

Which TWO of the following are valid Pod Security Standard levels? (Select 2)

Medium
120

A pod in the 'production' namespace is in a CrashLoopBackOff state. The pod has been running successfully for several days. You run 'kubectl describe pod app-pod -n production' and see the message: 'OOMKilled'. What is the MOST appropriate action to resolve this issue?

Medium
121

Which TWO of the following are valid approaches to restrict which nodes a pod can run on?

Hard
122

An administrator wants to restrict pods from running as root. Which admission controller should be enabled?

Easy
123

Which of the following host access settings should be avoided to minimize the attack surface from containers? (Select the setting that increases risk the most.)

Medium
124

You are creating a custom seccomp profile for a container that runs a binary requiring the 'write' syscall only. You place the profile JSON file at '/var/lib/kubelet/seccomp/profiles/write-only.json'. In the pod spec, which seccomp configuration correctly uses this profile?

Hard
125

A Kubernetes cluster uses containerd as the container runtime. The security team wants to restrict a specific container so it cannot create raw network packets. The container image runs as root and the Pod specification does not drop any capabilities. Which Linux capability should be dropped from the container's securityContext to prevent raw packet creation while still allowing binding to privileged ports?

Hard
126

An AppArmor profile is loaded in 'complain' mode. What happens when a pod with that profile attempts an action that violates the profile?

Hard
127

An administrator runs 'aa-status' on a node and sees a profile in 'complain' mode. What does this indicate?

Medium
128

Which THREE of the following are best practices for reducing the attack surface of a Kubernetes node?

Hard
129

Which of the following is the correct way to disable swap on a Kubernetes node to improve security?

Medium
130

Which of the following is the correct annotation to apply an AppArmor profile named 'my-profile' to a container named 'app' in a pod?

Easy
131

A cluster administrator wants to enforce Pod Security Standards at the namespace level using the built-in PodSecurity admission controller. The namespace 'test' should reject any pod that violates the 'baseline' level. Which command applies this correctly?

Medium
132

Which of the following seccomp profile types should be used to apply the container runtime's default seccomp profile?

Easy
133

Which THREE of the following are best practices for reducing the attack surface of Kubernetes nodes?

Medium
134

An administrator wants to prevent a container from accessing the host's network. Which pod security context field should be set to false?

Easy
135

A pod is scheduled on a node that has the AppArmor profile 'my-profile' loaded in complain mode. The pod annotation specifies 'localhost/my-profile' but the container is running without the profile being enforced. What is the most likely cause?

Hard
136

A cluster administrator has applied a PodSecurityPolicy (PSP) to restrict privileged containers. After upgrading to Kubernetes 1.25, they notice that PSPs are no longer working. What is the MOST likely reason?

Hard
137

Which command loads an AppArmor profile into the kernel?

Easy

Frequently asked questions

What does the System Hardening domain cover on the CKS exam?
Be able to edit a pod manifest to add AppArmor annotations, set seccompProfile, and drop capabilities, then verify with kubectl exec and node-level tools. The most important thing: confirm the profile is actually loaded and enforced, not just referenced.
How many questions are in this domain?
This page lists all 137 System Hardening questions in the CKS question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only System Hardening questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cncf-cks CNCF-CKS cks system hardening Practice Questions