Courseiva

CKS · topic practice

System Hardening practice questions

System Hardening covers reducing the attack surface of nodes and workloads: AppArmor and seccomp profiles, Linux capabilities, and Kubernetes Pod Security Admission. You are tested through hands-on tasks and multiple-choice items that require applying annotations, securityContext fields, and namespace labels correctly on a live cluster.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: System Hardening

What the exam tests

What to know about System Hardening

Be able to edit a pod manifest to add AppArmor annotations, set seccompProfile, and drop capabilities, then verify with kubectl exec and node-level tools. The most important thing: confirm the profile is actually loaded and enforced, not just referenced.

Applying AppArmor profiles via container.apparmor.security.beta.kubernetes.io/<container> annotations and verifying enforcement

Configuring seccompProfile (RuntimeDefault, Localhost) in a pod's securityContext and troubleshooting profile loading

Dropping Linux capabilities such as NET_RAW with securityContext.capabilities.drop and assessing the impact

Enforcing pod security defaults across a namespace using Pod Security Admission labels and restricted/baseline policies

Watch out for

Common System Hardening exam traps

  • ▸Assuming an AppArmor profile is enforced when the node has it in complain mode; complain mode only logs violations and does not block them.
  • ▸Forgetting that seccomp and AppArmor annotations are per-container, not per-pod, so a wrong container name silently leaves the profile unapplied.
  • ▸Believing NET_RAW is harmless; dropping it breaks tools like ping and raw-socket scanners, and some CNI or monitoring agents may rely on it.

Practice set

System Hardening questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full System Hardening explanation →

A cluster is running Kubernetes 1.24. The security team wants to enforce that all pods run with a read-only root filesystem. Which approach is most effective?

A developer wants to run a container that needs to modify kernel parameters. What is the secure way to achieve this?

You are a security engineer for a large e-commerce company. The Kubernetes cluster runs on-premises and hosts critical payment processing applications. Recently, a security scan revealed that several pods are running with privileged escalation enabled, and some have a writable root filesystem. The cluster uses Kubernetes v1.26 with PodSecurity admission controller enabled but currently set to 'privileged' profile for all namespaces. The development teams require flexibility for some legacy applications that need to run with hostNetwork or hostPID. However, the security team wants to enforce a restricted profile for most namespaces while allowing exceptions. The CISO has mandated that no pod should run as root, and all pods must have read-only root filesystem and privilege escalation disabled. Additionally, any pod that requires hostNetwork or hostPID must be explicitly approved and placed in a separate namespace. You need to design a solution that meets these requirements with minimal operational overhead. What is the best course of action?

A security engineer is hardening a Kubernetes node and wants to ensure that kubelet does not accept requests from unauthorized sources. Which kubelet configuration change should be made?

Question 5mediummultiple choice
Read the full System Hardening explanation →

During a security audit, it is found that containers running in a cluster have CAP_NET_RAW capability by default. The team wants to drop this capability for all containers. Which approach should be taken?

Question 6mediummultiple choice
Read the full System Hardening explanation →

Refer to the exhibit. The pod fails to start with the error 'container has runAsNonRoot but image will run as root'. Which change would fix the issue?

Exhibit

Refer to the exhibit.
```
apiVersion: v1
kind: Pod
metadata:
  name: nginx
spec:
  containers:
  - name: nginx
    image: nginx:1.21
    securityContext:
      runAsNonRoot: true
      runAsUser: 1000
      capabilities:
        add: ["NET_ADMIN"]
```

A security team wants to ensure that no pod runs with privileged access. They have created a PodSecurityPolicy (PSP) that sets 'privileged: false'. However, a pod with privileged: true still gets created. What is the most likely cause?

Question 8mediummultiple choice
Read the full System Hardening explanation →

A security policy requires that containers should drop all capabilities and only add back the specific capabilities needed. Which YAML snippet correctly implements this for a container?

You need to apply a Pod Security Standard that prevents containers from running as root and disallows privileged escalation. Which TWO levels enforce these requirements?

Question 10mediummultiple choice
Read the full System Hardening explanation →

A security engineer needs to apply a custom AppArmor profile to a pod. The profile is named 'k8s-apparmor-example-deny-write' and is loaded on the node. Which annotation should be added to the pod's metadata to enforce this profile?

Which kubectl command is used to check the AppArmor status on a Kubernetes node?

Which Linux capability should be dropped to prevent a container from gaining new privileges via setuid binaries?

Which of the following is the correct way to drop all capabilities from a container in a pod specification?

Question 14mediummultiple choice
Read the full System Hardening explanation →

A cluster has PodSecurity admission enabled. A developer creates a pod with the following security context: 'securityContext: { capabilities: { drop: ["ALL"], add: ["NET_ADMIN"] } }'. The namespace is labeled 'pod-security.kubernetes.io/enforce: baseline'. Will the pod be allowed?

A pod is in a Pending state with the event: 'failed to generate spec: failed to validate seccomp profile: seccomp profile not found'. The profile is stored at /var/lib/kubelet/seccomp/custom.json on the node. Which of the following is the MOST likely cause?

Which of the following Pod specification settings prevents a container from using the host network namespace?

Question 17mediummultiple choice
Read the full System Hardening explanation →

An administrator runs 'kubectl run test-pod --image=nginx --dry-run=client -o yaml > pod.yaml', then adds 'hostPID: true' and 'hostNetwork: true' to the pod's spec. After applying with 'kubectl apply -f pod.yaml', the pod is created but immediately goes into 'CrashLoopBackOff'. What is the likely cause?

Which TWO of the following are valid methods to apply a seccomp profile to a pod in Kubernetes?

Question 19mediummultiple choice
Read the full System Hardening explanation →

A pod spec includes the following securityContext:

securityContext: seccompProfile: type: Localhost localhostProfile: custom-profile.json

Where should the custom seccomp profile 'custom-profile.json' be placed on the node?

A cluster administrator wants to prevent all containers in a namespace from running with the NET_RAW capability. They plan to use a PodSecurityPolicy (PSP) but PSP is deprecated. Which approach should they use instead?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused System Hardening sessions

Start a System Hardening only practice session

Every question in these sessions is drawn from the System Hardening domain — nothing else.

Related practice questions

Related CKS topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CKS exam test about System Hardening?
Be able to edit a pod manifest to add AppArmor annotations, set seccompProfile, and drop capabilities, then verify with kubectl exec and node-level tools. The most important thing: confirm the profile is actually loaded and enforced, not just referenced.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just System Hardening questions in a focused session?
Yes — the session launcher on this page draws every question from the System Hardening domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CKS topics?
Use the topic links above to move to related areas, or go back to the CKS question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CKS exam covers. They are not copied from any real exam or dump site.