CKS System Hardening Practice Question
Exhibit
Refer to the exhibit.
```
$ kubectl get nodes -o yaml | grep -A10 kubeletConfig
kubeletConfig:
imageGCHighThresholdPercent: 85
imageGCLowThresholdPercent: 80
maxPods: 110
podPidsLimit: -1
resolvConf: /etc/resolv.conf
rotateCertificates: true
```Refer to the exhibit. A security engineer sees that podPidsLimit is set to -1. What security concern does this raise?
⚠ Common exam trap
Test-takers frequently assume `-1` means 'no limit' is safe or that it enforces a default, but the CKS exam tests the specific security implication of disabling PID limiting, which is the risk of a fork bomb and node-wide DoS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It disables PID limiting, allowing a single pod to consume all PIDs on the node, risking a fork bomb
Setting `podPidsLimit` to `-1` in Kubernetes disables PID limiting for pods, meaning a single pod can create an unlimited number of processes. This poses a security risk because a compromised or malicious pod could launch a fork bomb, exhausting all available PIDs on the node and causing a denial of service (DoS) for other workloads. The correct answer is C.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It sets a hard limit of 1 PID per pod, which may break workloads
Why it's wrong here
A value of -1 disables the PID cgroup limit entirely, so a fork bomb inside the pod can exhaust node PIDs and starve other workloads. It is tempting because a positive integer such as 1 would indeed be a hard per-pod cap, but that is not what -1 represents.
- ✗
It limits each container to 1000 PIDs
Why it's wrong here
A podPidsLimit of -1 means unlimited PIDs, so no cap of 1000 exists; the value disables the limit entirely, enabling fork-bomb denial of service. A numeric cap such as 1000 would be the hardened setting, which is why this distractor tempts.
- ✓
It disables PID limiting, allowing a single pod to consume all PIDs on the node, risking a fork bomb
Why this is correct
A podPidsLimit of -1 removes the cgroup pids.max cap entirely, so the container can spawn unlimited processes. A fork bomb inside that pod would exhaust the node's PID table, starving kubelet and other workloads of process IDs.
- ✗
It enforces a default PID limit of 100 per pod
Why it's wrong here
A value of -1 means no PID limit is enforced, not a default of 100; unlimited PIDs allow fork-bomb exhaustion of the node. Setting an explicit positive value such as 100 would be the correct hardening choice, which makes this option tempting, but -1 does not apply any default.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.