Courseiva

CKS · topic practice

Minimize Microservice Vulnerabilities practice questions

This domain covers hardening the container layer itself: choosing and configuring sandboxed runtimes, keeping secrets out of environment variables, and applying pod-level security controls. On the CKS exam you are given a live cluster and must create RuntimeClass objects, wire them into pods, mount Secrets as volumes, and reason about gVisor and Kata Containers behavior under kubectl and YAML edits.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Minimize Microservice Vulnerabilities

What the exam tests

What to know about Minimize Microservice Vulnerabilities

Be able to create a RuntimeClass, attach it to a workload with runtimeClassName, and mount a Secret as a read-only volume. The single most important thing: verify the runtime handler actually exists on the node before scheduling, or the Pod will never start.

Creating a RuntimeClass object and referencing it via runtimeClassName in a Pod spec

Mounting a Kubernetes Secret as a volume instead of exposing it through env or envFrom

Distinguishing gVisor and Kata Containers sandboxing from standard runc isolation

Applying Pod Security Admission labels and securityContext fields to restrict workloads

Watch out for

Common Minimize Microservice Vulnerabilities exam traps

  • ▸Setting runtimeClassName on a Pod without first creating the RuntimeClass object, or misspelling the handler name so the Pod stays Pending
  • ▸Using env or envFrom for Secrets and believing base64 encoding hides the value; it is trivially decoded from the manifest
  • ▸Assuming gVisor or Kata Containers replace Kubernetes RBAC, NetworkPolicy, or Secret encryption rather than adding kernel-level isolation

Practice set

Minimize Microservice Vulnerabilities questions

20 questions · select your answer, then reveal the explanation

Which TWO of the following are effective measures to minimize the impact of a compromised microservice container in a Kubernetes cluster? (Choose two.)

You are a platform engineer at a financial services company. The production cluster runs a set of microservices that handle sensitive customer data. The cluster has been configured with Pod Security Standards (PSS) enforced via OPA/Gatekeeper. Recently, the security team identified that a new deployment of the `payment-processing` microservice is running with the `seccomp` profile set to `Unconfined`. This violates the company policy that requires all containers to use a runtime default seccomp profile. The deployment YAML does not explicitly set any security context for seccomp. The cluster's nodes are running containerd 1.6 with default seccomp profile enabled. The OPA constraint template checks that `securityContext.seccompProfile.type` is set to `RuntimeDefault` or `Localhost`. However, the deployment passes the OPA validation. What is the most likely reason the deployment is not being rejected by OPA, and how should you fix it?

Arrange the steps to configure and use Trivy to scan container images for vulnerabilities in a CI/CD pipeline.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Which of the following OPA Gatekeeper Rego policies would deny a pod that sets `securityContext.runAsUser: 0`?

Which Kubernetes admission controller is responsible for mutating and validating pod requests based on policies defined by OPA Gatekeeper?

A cluster administrator wants to ensure that all pods in a namespace run with the `seccomp` profile set to `RuntimeDefault`. Which OPA Gatekeeper ConstraintTemplate would achieve this?

You are deploying a microservice that must run as a non-root user and have a read-only root filesystem. Which two fields must be set in the PodSecurityContext or container SecurityContext?

A security engineer wants to encrypt secrets at rest in an existing Kubernetes cluster. The cluster is already running with the default encryption configuration. After creating an EncryptionConfiguration resource and updating the kube-apiserver manifest, which command should be used to ensure the new configuration is applied without restarting the API server?

A pod is failing with 'CrashLoopBackOff'. The pod's securityContext includes 'allowPrivilegeEscalation: false'. The container image is built with a default user of root and attempts to change capabilities. What is the most likely cause of the crash?

You have an existing deployment that uses environment variables for secrets. Which kubectl command can be used to update the deployment to mount secrets as volumes without recreating the pods?

Which TWO of the following are valid ways to reduce the attack surface of a container? (Select TWO)

An administrator needs to enforce that all pods in a namespace run with read-only root filesystem. Which Pod Security Standard should be applied?

A pod is running with the following security context:

```yaml securityContext: allowPrivilegeEscalation: false runAsNonRoot: true seccompProfile: type: RuntimeDefault ```

The pod is in a CrashLoopBackOff. The logs show: "exec user process caused: operation not permitted". What is the most likely cause?

A security best practice is to avoid storing secrets in environment variables. Which is a secure alternative for injecting secrets into a pod?

You have deployed a service mesh with Istio and want to enforce mutual TLS (mTLS) for all traffic between services in the 'mesh' namespace. Which resource should you create?

Which command creates a ResourceQuota in the 'team-a' namespace?

A pod fails to start with 'CrashLoopBackOff'. The pod's YAML includes securityContext: { allowPrivilegeEscalation: false, capabilities: { drop: ['ALL'] } }. What is the likely cause?

A pod's container tries to read environment variables that contain database credentials. The cluster has an external secrets manager (HashiCorp Vault) integrated via a sidecar. Which approach is MOST secure for exposing secrets to the container?

An OPA Gatekeeper ConstraintTemplate uses a Rego rule that denies pods without a specific label. The Constraint is created but pods without the label are still being allowed. What is the MOST likely cause?

Which of the following is a best practice for storing sensitive information like database passwords in Kubernetes?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Minimize Microservice Vulnerabilities sessions

Start a Minimize Microservice Vulnerabilities only practice session

Every question in these sessions is drawn from the Minimize Microservice Vulnerabilities domain — nothing else.

Related practice questions

Related CKS topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CKS exam test about Minimize Microservice Vulnerabilities?
Be able to create a RuntimeClass, attach it to a workload with runtimeClassName, and mount a Secret as a read-only volume. The single most important thing: verify the runtime handler actually exists on the node before scheduling, or the Pod will never start.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Minimize Microservice Vulnerabilities questions in a focused session?
Yes — the session launcher on this page draws every question from the Minimize Microservice Vulnerabilities domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CKS topics?
Use the topic links above to move to related areas, or go back to the CKS question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CKS exam covers. They are not copied from any real exam or dump site.