Courseiva

CKS · domain

Cluster Hardening

Cluster Hardening covers the controls that keep a Kubernetes cluster's own components and API surface resistant to compromise. For the CKS exam you work hands-on inside a live cluster: restricting API access, tightening RBAC, protecting kubelet endpoints, and upgrading components safely. Tasks are performance-based, so you must know the exact kubectl, kubeadm and systemd commands and apply them under time pressure.

20 questions4 easy10 medium6 hard

Focused practice

Practice Cluster Hardening questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Cluster Hardening

Use kubectl auth can-i, RBAC RoleBindings, and kubelet --anonymous-auth=false to lock down API and node access. Get RBAC least privilege right, then upgrade control plane components with kubeadm upgrade.

Minimising RBAC permissions by removing wildcards, cluster-admin bindings and unnecessary default ServiceAccount rights

Securing the kubelet API with authentication, authorization and read-only port disabled via kubelet config

Restricting API server access using anonymous-auth, authorization modes and network exposure controls

Performing safe cluster upgrades with kubeadm upgrade plan, apply and node drain/uncordon sequencing

Watch out for

Common Cluster Hardening exam traps

  • ▸Leaving the kubelet read-only port 10255 open, or not disabling anonymous authentication on kubelet endpoints
  • ▸Granting cluster-admin or wildcard verbs in Role/ClusterRole instead of least-privilege rules scoped to resources
  • ▸Upgrading worker nodes before the control plane, or skipping kubeadm upgrade plan and etcd backups

Question index

All Cluster Hardening questions (20)

Click any question to see the full explanation, or start a practice session above.

1

A cluster uses RBAC and a ServiceAccount 'monitor' in namespace 'observability'. The account needs to list pods in all namespaces. Which ClusterRole and binding should be created?

Medium
2

You are the security engineer for a multi-tenant Kubernetes cluster. The cluster uses kubeadm and runs Kubernetes v1.24. Each tenant has a dedicated namespace. A new tenant, 'acme-corp', requires that all pods in their namespace run with a read-only root filesystem and must not be able to escalate privileges. They also need to run a legacy container that must listen on a port below 1024. The cluster currently uses PodSecurityPolicy (PSP) but is planning to migrate to Pod Security Admission (PSA). The legacy container needs to run as non-root with the NET_BIND_SERVICE capability to bind to port 80. You need to configure security policies for the 'acme-corp' namespace without affecting other tenants. Which approach best meets these requirements while following Kubernetes best practices?

Hard
3

An operator must upgrade a kubeadm cluster and wants to verify that the new control plane binaries are authentic before installing them. The team already has the Kubernetes release signing key. Which step confirms the integrity and origin of the downloaded binary?

Medium
4

A security team is hardening a cluster where the kube-apiserver is started with the flag --authorization-mode=Node,RBAC. A penetration test reveals that kubelet authentication is using anonymous requests and the webhook authorizer is not enabled. To ensure that kubelet API requests are authenticated and authorized, which combination of kubelet configuration changes should be applied?

Medium
5

Which THREE of the following are required to secure etcd in a Kubernetes cluster?

Hard
6

Which TWO of the following are best practices for securing container images?

Easy
7

A security team wants to ensure that all pods in a namespace run with a restricted seccomp profile. Which Pod Security Standard admission controller mode should be used to enforce this without blocking necessary pods?

Hard
8

Which THREE of the following are valid methods to enforce pod security standards in a Kubernetes cluster?

Hard
9

Which TWO of the following are valid ways to restrict access to the Kubernetes API server?

Medium
10

A Kubernetes administrator is reviewing the cluster's RBAC configuration and notices that a ClusterRoleBinding grants the cluster-admin role to the system:anonymous user. What is the most immediate and appropriate action to harden the cluster?

Easy
11

A security review flags that developers can create pods that mount the host's /etc directory. You need to block hostPath volumes cluster-wide without breaking existing workloads that use the CSI driver for persistent storage. Which control is appropriate?

Medium
12

A cluster has a PodSecurityPolicy that requires 'RunAsAny' for the user. An administrator wants to enforce that all pods in namespace 'production' must run with a specific seccomp profile. Which approach is recommended given PSP is deprecated?

Hard
13

Arrange the steps to enable and configure audit logging in Kubernetes.

Medium
14

Match each Kubernetes security tool or feature to its purpose.

Medium
15

Which Kubernetes resource should be used to restrict egress traffic from pods?

Easy
16

A pod is failing to start with: 'Error: container has runAsNonRoot and image will run as root'. The pod spec sets securityContext.runAsNonRoot: true. The container image is 'nginx:latest' which runs as root. Which change allows the pod to run while maintaining security?

Hard
17

A developer created a ClusterRole 'pod-reader' with rules to get, list, and watch pods, and bound it to a user. The user reports they cannot list pods in namespace 'test', although the same commands work in the 'default' namespace. What is the most likely cause?

Medium
18

A company uses kube-bench to scan their cluster. The report shows a warning: 'Ensure that the --authorization-mode argument is set to Node,RBAC'. What is the best way to fix this?

Medium
19

An administrator wants to prevent pods from running as root. Which SecurityContext field should be set at the pod level?

Easy
20

You are hardening a kubeadm-managed cluster running Kubernetes v1.28. The kubelet's read-only port (10255) is still listening on every node, exposing pod and node metadata without authentication. You must disable it across the cluster. Which action is correct?

Medium

Frequently asked questions

What does the Cluster Hardening domain cover on the CKS exam?
Use kubectl auth can-i, RBAC RoleBindings, and kubelet --anonymous-auth=false to lock down API and node access. Get RBAC least privilege right, then upgrade control plane components with kubeadm upgrade.
How many questions are in this domain?
This page lists all 20 Cluster Hardening questions in the CKS question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cluster Hardening questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cncf-cks CNCF-CKS cluster hardening Practice Questions