Courseiva
System Hardening →easyMultiple Choice

CKS System Hardening Practice Question

Exhibit

Refer to the exhibit.
```
$ kubectl get nodes -o yaml | grep -A10 kubeletConfig
    kubeletConfig:
      imageGCHighThresholdPercent: 85
      imageGCLowThresholdPercent: 80
      maxPods: 110
      podPidsLimit: -1
      resolvConf: /etc/resolv.conf
      rotateCertificates: true
```

Refer to the exhibit. A security engineer sees that podPidsLimit is set to -1. What security concern does this raise?

⚠ Common exam trap

Test-takers frequently assume `-1` means 'no limit' is safe or that it enforces a default, but the CKS exam tests the specific security implication of disabling PID limiting, which is the risk of a fork bomb and node-wide DoS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It disables PID limiting, allowing a single pod to consume all PIDs on the node, risking a fork bomb

Setting `podPidsLimit` to `-1` in Kubernetes disables PID limiting for pods, meaning a single pod can create an unlimited number of processes. This poses a security risk because a compromised or malicious pod could launch a fork bomb, exhausting all available PIDs on the node and causing a denial of service (DoS) for other workloads. The correct answer is C.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It sets a hard limit of 1 PID per pod, which may break workloads

    Why it's wrong here

    A value of -1 disables the PID cgroup limit entirely, so a fork bomb inside the pod can exhaust node PIDs and starve other workloads. It is tempting because a positive integer such as 1 would indeed be a hard per-pod cap, but that is not what -1 represents.

  • ✗

    It limits each container to 1000 PIDs

    Why it's wrong here

    A podPidsLimit of -1 means unlimited PIDs, so no cap of 1000 exists; the value disables the limit entirely, enabling fork-bomb denial of service. A numeric cap such as 1000 would be the hardened setting, which is why this distractor tempts.

  • ✓

    It disables PID limiting, allowing a single pod to consume all PIDs on the node, risking a fork bomb

    Why this is correct

    A podPidsLimit of -1 removes the cgroup pids.max cap entirely, so the container can spawn unlimited processes. A fork bomb inside that pod would exhaust the node's PID table, starving kubelet and other workloads of process IDs.

  • ✗

    It enforces a default PID limit of 100 per pod

    Why it's wrong here

    A value of -1 means no PID limit is enforced, not a default of 100; unlimited PIDs allow fork-bomb exhaustion of the node. Setting an explicit positive value such as 100 would be the correct hardening choice, which makes this option tempting, but -1 does not apply any default.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.