Sample questions
Certified Kubernetes Security Specialist CKS practice questions
A DevOps team uses a CI/CD pipeline to build container images and push them to a private registry. To minimize the risk of supply chain attacks, which of the following is the most…
Which of the following YAML snippets correctly configures a ServiceAccount with automountServiceAccountToken set to false?
Arrange the steps to create and enforce a Pod Security Policy (PSP) in a Kubernetes cluster.
Which tool is used to generate a Software Bill of Materials (SBOM) for a container image?
You are auditing RBAC and find a ClusterRoleBinding named 'admin-binding' that binds the 'cluster-admin' ClusterRole to a service account in the 'default' namespace. What is the se…
A security policy requires that all container images use SHA-based digests instead of tags. Which approach ensures this in a Deployment YAML?
A pod in namespace 'ns1' has automountServiceAccountToken: false. However, the container still has a mounted service account token at /var/run/secrets/kubernetes.io/serviceaccount.…
You are responding to a security incident where a pod named `compromised-pod` in namespace `default` is suspected of being used for cryptocurrency mining. You need to immediately i…
Monitoring, Logging and Runtime SecuritymediumSee the answer and why each option is right or wrong →Which annotation is used to apply an AppArmor profile to a pod in Kubernetes?
A pod is scheduled on a node that has the AppArmor profile 'my-profile' loaded in complain mode. The pod annotation specifies 'localhost/my-profile' but the container is running wi…
An admin runs 'kubectl auth reconcile -f rbac.yaml' and gets an error that the user does not have permission to create ClusterRoleBindings. What is the most likely cause?
Which of the following is correct about dropping the 'NET_RAW' capability?
You need to use gVisor as a container runtime for a set of workloads in the cluster. Which Kubernetes resource must be created to reference the runtime class?
A DevOps engineer wants to ensure that all pods in a namespace have seccomp set to RuntimeDefault unless explicitly overridden. Which approach should be used to enforce this?
An administrator wants to ensure that a service account used by a deployment cannot automatically mount its token. Which field should be set to `false` in the Pod spec?
An administrator wants to enforce that all pods in a namespace use the restricted Pod Security Standard. Which of the following commands correctly enables this enforcement?
What is the purpose of the 'automountServiceAccountToken: false' setting in a Pod spec?
You suspect a pod is making unexpected outbound connections. Which tool can you use to inspect network connections from within the container?
Monitoring, Logging and Runtime SecuritymediumSee the answer and why each option is right or wrong →A pod is stuck in Pending state. 'kubectl describe pod' shows the event: '0/4 nodes are available: 1 node had taint {node-role.kubernetes.io/control-plane: }, that the pod didn't t…
During a security audit, it was found that some pods have access to the host network. How can an administrator restrict host network access for all pods in the cluster?
A security best practice is to avoid storing sensitive data in environment variables. Instead, secrets should be mounted as volumes. Which of the following YAML snippets correctly…
Which kube-apiserver flag enables encryption at rest for secrets?
An attacker exploited a container escape vulnerability. The team wants to mitigate such attacks by restricting containers from accessing the host's kernel capabilities. Which set o…
Which etcd security measure should be implemented to ensure only authorized clients can access the etcd cluster?