Courseiva
← Back to Certified Kubernetes Security Specialist CKS questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Certified Kubernetes Security Specialist CKS practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CKS
exam code
CNCF
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CKS topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

Which THREE of the following are features of container sandboxing solutions like gVisor or Kata Containers?

Question 2mediummulti select
Full question →

Which TWO of the following are valid ways to securely manage secrets in Kubernetes? (Choose two.)

Question 3easymulti select
Full question →

Which TWO container sandboxing technologies are supported in Kubernetes via RuntimeClass? (Choose two)

Question 4easymulti select
Full question →

Which TWO of the following are valid methods to securely manage secrets in Kubernetes?

Question 5mediummulti select
Full question →

Which TWO of the following are valid ways to enforce that a container runs as a non-root user?

Question 6mediummulti select
Full question →

Which TWO of the following are valid methods to verify the integrity of a container image? (Select 2)

Question 7mediummulti select
Full question →

Which two of the following are correct ways to enforce least privilege for service accounts? (Choose two.)

Question 8hardmulti select
Full question →

Which THREE of the following are best practices for securing a Kubernetes cluster using OPA Gatekeeper? (Choose three.)

Question 9mediummulti select
Full question →

Which TWO resources can be used to implement RBAC in Kubernetes?

Question 10hardmulti select
Full question →

Which TWO of the following are effective measures to harden the Kubernetes API server against unauthorized access?

Question 11mediummulti select
Full question →

Which TWO are valid stages in a Kubernetes audit event? (Select 2)

Question 12hardmulti select
Full question →

Which THREE of the following are correct statements about seccomp in Kubernetes? (Select 3)

Question 13mediummulti select
Full question →

Which TWO of the following are valid Pod Security Standard levels? (Select 2)

Question 14hardmulti select
Full question →

Which THREE of the following are valid flags for enabling admission plugins on the API server?

Question 15mediummulti select
Full question →

Which TWO of the following are recommendations from the CIS Kubernetes Benchmark?

Question 16hardmulti select
Full question →

Which THREE of the following are recommended measures to reduce the attack surface of Kubernetes nodes?

Question 17hardmulti select
Full question →

Which THREE of the following are required to secure etcd in a Kubernetes cluster?

Question 18mediummulti select
Full question →

Which TWO of the following are valid arguments for the kubectl command to create a secret from a file? (Select TWO)

Question 19mediummulti select
Full question →

Which TWO AppArmor modes are available? (Select 2)

Question 20easymulti select
Full question →

You are asked to secure a set of microservices running in a Kubernetes cluster. Which TWO of the following practices help minimize vulnerabilities in microservices?

These CKS practice questions are part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style CKS questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.