CKS · domain
Cluster Hardening
Cluster Hardening covers the controls that keep a Kubernetes cluster's own components and API surface resistant to compromise. For the CKS exam you work hands-on inside a live cluster: restricting API access, tightening RBAC, protecting kubelet endpoints, and upgrading components safely. Tasks are performance-based, so you must know the exact kubectl, kubeadm and systemd commands and apply them under time pressure.
Focused practice
Practice Cluster Hardening questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Cluster Hardening
Use kubectl auth can-i, RBAC RoleBindings, and kubelet --anonymous-auth=false to lock down API and node access. Get RBAC least privilege right, then upgrade control plane components with kubeadm upgrade.
Minimising RBAC permissions by removing wildcards, cluster-admin bindings and unnecessary default ServiceAccount rights
Securing the kubelet API with authentication, authorization and read-only port disabled via kubelet config
Restricting API server access using anonymous-auth, authorization modes and network exposure controls
Performing safe cluster upgrades with kubeadm upgrade plan, apply and node drain/uncordon sequencing
Watch out for
Common Cluster Hardening exam traps
- ▸Leaving the kubelet read-only port 10255 open, or not disabling anonymous authentication on kubelet endpoints
- ▸Granting cluster-admin or wildcard verbs in Role/ClusterRole instead of least-privilege rules scoped to resources
- ▸Upgrading worker nodes before the control plane, or skipping kubeadm upgrade plan and etcd backups
Question index
All Cluster Hardening questions (20)
Click any question to see the full explanation, or start a practice session above.
A cluster uses RBAC and a ServiceAccount 'monitor' in namespace 'observability'. The account needs to list pods in all namespaces. Which ClusterRole and binding should be created?
Medium2You are the security engineer for a multi-tenant Kubernetes cluster. The cluster uses kubeadm and runs Kubernetes v1.24. Each tenant has a dedicated namespace. A new tenant, 'acme-corp', requires that all pods in their namespace run with a read-only root filesystem and must not be able to escalate privileges. They also need to run a legacy container that must listen on a port below 1024. The cluster currently uses PodSecurityPolicy (PSP) but is planning to migrate to Pod Security Admission (PSA). The legacy container needs to run as non-root with the NET_BIND_SERVICE capability to bind to port 80. You need to configure security policies for the 'acme-corp' namespace without affecting other tenants. Which approach best meets these requirements while following Kubernetes best practices?
Hard3An operator must upgrade a kubeadm cluster and wants to verify that the new control plane binaries are authentic before installing them. The team already has the Kubernetes release signing key. Which step confirms the integrity and origin of the downloaded binary?
Medium4A security team is hardening a cluster where the kube-apiserver is started with the flag --authorization-mode=Node,RBAC. A penetration test reveals that kubelet authentication is using anonymous requests and the webhook authorizer is not enabled. To ensure that kubelet API requests are authenticated and authorized, which combination of kubelet configuration changes should be applied?
Medium5Which THREE of the following are required to secure etcd in a Kubernetes cluster?
Hard6Which TWO of the following are best practices for securing container images?
Easy7A security team wants to ensure that all pods in a namespace run with a restricted seccomp profile. Which Pod Security Standard admission controller mode should be used to enforce this without blocking necessary pods?
Hard8Which THREE of the following are valid methods to enforce pod security standards in a Kubernetes cluster?
Hard9Which TWO of the following are valid ways to restrict access to the Kubernetes API server?
Medium10A Kubernetes administrator is reviewing the cluster's RBAC configuration and notices that a ClusterRoleBinding grants the cluster-admin role to the system:anonymous user. What is the most immediate and appropriate action to harden the cluster?
Easy11A security review flags that developers can create pods that mount the host's /etc directory. You need to block hostPath volumes cluster-wide without breaking existing workloads that use the CSI driver for persistent storage. Which control is appropriate?
Medium12A cluster has a PodSecurityPolicy that requires 'RunAsAny' for the user. An administrator wants to enforce that all pods in namespace 'production' must run with a specific seccomp profile. Which approach is recommended given PSP is deprecated?
Hard13Arrange the steps to enable and configure audit logging in Kubernetes.
Medium14Match each Kubernetes security tool or feature to its purpose.
Medium15Which Kubernetes resource should be used to restrict egress traffic from pods?
Easy16A pod is failing to start with: 'Error: container has runAsNonRoot and image will run as root'. The pod spec sets securityContext.runAsNonRoot: true. The container image is 'nginx:latest' which runs as root. Which change allows the pod to run while maintaining security?
Hard17A developer created a ClusterRole 'pod-reader' with rules to get, list, and watch pods, and bound it to a user. The user reports they cannot list pods in namespace 'test', although the same commands work in the 'default' namespace. What is the most likely cause?
Medium18A company uses kube-bench to scan their cluster. The report shows a warning: 'Ensure that the --authorization-mode argument is set to Node,RBAC'. What is the best way to fix this?
Medium19An administrator wants to prevent pods from running as root. Which SecurityContext field should be set at the pod level?
Easy20You are hardening a kubeadm-managed cluster running Kubernetes v1.28. The kubelet's read-only port (10255) is still listening on every node, exposing pod and node metadata without authentication. You must disable it across the cluster. Which action is correct?
MediumOther domains
All CKS exam domains
Frequently asked questions
- What does the Cluster Hardening domain cover on the CKS exam?
- Use kubectl auth can-i, RBAC RoleBindings, and kubelet --anonymous-auth=false to lock down API and node access. Get RBAC least privilege right, then upgrade control plane components with kubeadm upgrade.
- How many questions are in this domain?
- This page lists all 20 Cluster Hardening questions in the CKS question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cluster Hardening questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.