Courseiva

CKS · topic practice

Cluster Setup practice questions

Cluster Setup is 15% of the CKS exam and covers hardening the Kubernetes control plane and worker nodes. You will perform live tasks in a terminal: applying NetworkPolicies, configuring API server admission controls, securing Ingress, and running kube-bench or CIS benchmark checks. Expect hands-on editing of manifests and verifying behaviour with kubectl rather than multiple-choice recall.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
15 questionsDomain: Cluster Setup

What the exam tests

What to know about Cluster Setup

Apply NetworkPolicies, configure API server admission plugins, secure Ingress with TLS, and run kube-bench. The critical thing: verify your NetworkPolicy actually blocks traffic using kubectl exec between pods.

Creating NetworkPolicy objects to restrict pod ingress and egress by namespace, label, and port

Enabling and configuring admission controllers such as NodeRestriction and PodSecurity admission on the API server

Hardening Ingress with TLS, and restricting access using NetworkPolicy or Ingress annotations

Running CIS benchmark tooling like kube-bench and remediating control plane and kubelet findings

Watch out for

Common Cluster Setup exam traps

  • ▸Writing a NetworkPolicy that selects pods but forgets a matching egress or ingress rule, leaving traffic default-allowed in the other direction
  • ▸Editing API server flags in a static pod manifest but not restarting the kubelet or verifying the change took effect
  • ▸Assuming a default-deny NetworkPolicy blocks all traffic cluster-wide, when it only affects pods selected in that namespace

Practice set

Cluster Setup questions

15 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Read the full Cluster Setup explanation →

During a cluster upgrade, the kubelet on a worker node fails to start after updating the kubelet binary. The kubelet logs show: 'failed to load bootstrap client certificate: open /var/lib/kubelet/pki/kubelet-client-current.pem: no such file or directory'. What is the most likely cause?

Which TWO of the following are valid methods to secure the etcd cluster in a Kubernetes setup?

Which THREE of the following are required when setting up a Kubernetes control plane with kubeadm for a production environment?

Question 4hardmultiple choice
Read the full Cluster Setup explanation →

You are responsible for securing a multi-tenant Kubernetes cluster that uses kubeadm for bootstrapping. The cluster has three control plane nodes and five worker nodes, all running Ubuntu 22.04. A recent security scan discovered that the etcd data directory is not encrypted at rest. The cluster stores sensitive customer data in secrets. You plan to enable encryption at rest for etcd. You have already created an encryption configuration file and placed it at /etc/kubernetes/encryption-config.yaml. The cluster is currently running Kubernetes v1.28.0 with etcd v3.5.9. You need to ensure that all existing and new secrets are encrypted. You also want to minimize downtime. Which of the following steps should you take?

Question 5mediummultiple choice
Read the full Cluster Setup explanation →

A CKS candidate is asked to verify that the kube-apiserver on a production cluster does not expose any insecure endpoints. The candidate runs 'kubectl get pods -n kube-system -l component=kube-apiserver -o yaml' and inspects the container command. Which flag value should the candidate confirm is NOT present in the kube-apiserver command line to ensure the insecure port is disabled?

A security engineer is reviewing a cluster's NetworkPolicy configuration to reduce lateral movement. The engineer wants to confirm that a default-deny posture is in place for a namespace called 'backend'. Which TWO actions should the engineer take to establish a default-deny for both ingress and egress traffic in that namespace? (Choose two.)

Question 7easymultiple choice
Read the full Cluster Setup explanation →

A Kubernetes administrator needs to verify that the kubelet is configured to use a secure TLS certificate for its API server. Which file should be checked for the kubelet's certificate authority and client certificate settings?

Question 8easymultiple choice
Read the full Cluster Setup explanation →

A team needs to set up a highly available Kubernetes control plane across three availability zones. What is the minimum number of etcd members required to achieve fault tolerance against one zone failure?

Question 9mediummultiple choice
Read the full Cluster Setup explanation →

A security audit reveals that the kube-apiserver is using the default insecure port 8080 on a production cluster. Which is the most secure and recommended remediation?

Question 10easymultiple choice
Read the full Cluster Setup explanation →

A cluster is using kubeadm and the control plane components are running as static pods. Where are the static pod manifests for the API server located by default?

Question 11mediummultiple choice
Read the full Cluster Setup explanation →

A security team wants to ensure that all communication between the kubelet and the API server is encrypted. Which flag must be set on the kubelet to enforce this?

Order the steps to rotate a Kubernetes API server certificate.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each Kubernetes admission controller to its role in security.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Limits the Node and Pod objects a kubelet can modify

Ensures images are always pulled, preventing use of local images

Denies pods with certain security context settings (deprecated)

Implements automation for service accounts

Enforces namespace-level node selector restrictions

Question 14hardmultiple choice
Read the full Cluster Setup explanation →

A platform team runs a multi-tenant cluster and wants to enforce that all newly created Pods in the 'payments' namespace must run as non-root and must drop all Linux capabilities. The team decides to use a Pod Security Admission (PSA) label on the namespace. Which label value should they apply to the namespace to enforce these restrictions while still allowing other namespaces to remain unrestricted?

Question 15hardmultiple choice
Read the full Cluster Setup explanation →

A cluster administrator wants to enforce that all newly created pods in the 'production' namespace run with a read-only root filesystem. The cluster uses Kubernetes 1.25+ and the Pod Security Admission controller is enabled with the baseline and restricted profiles. Which namespace label must be applied to enforce the restricted policy?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cluster Setup sessions

Start a Cluster Setup only practice session

Every question in these sessions is drawn from the Cluster Setup domain — nothing else.

Related practice questions

Related CKS topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CKS exam test about Cluster Setup?
Apply NetworkPolicies, configure API server admission plugins, secure Ingress with TLS, and run kube-bench. The critical thing: verify your NetworkPolicy actually blocks traffic using kubectl exec between pods.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cluster Setup questions in a focused session?
Yes — the session launcher on this page draws every question from the Cluster Setup domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CKS topics?
Use the topic links above to move to related areas, or go back to the CKS question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CKS exam covers. They are not copied from any real exam or dump site.