Courseiva
hardMultiple Select

CKS Practice Question: Which THREE practices help ensure the integrity…

Which THREE practices help ensure the integrity and confidentiality of container logs in a Kubernetes cluster?

⚠ Common exam trap

CNCF often tests the misconception that disabling log rotation improves security, but in reality, rotation is a standard operational practice that does not inherently compromise integrity; the trap is confusing operational controls with security controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the log collector to use TLS when shipping logs to a central system.

Configuring the log collector to use TLS (e.g., Fluentd with TLS output plugin or Filebeat with SSL/TLS) encrypts log data in transit, preventing eavesdropping or tampering during shipping to a central system like Elasticsearch or Splunk. This directly protects confidentiality and integrity against man-in-the-middle attacks on the network path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the log collector to use TLS when shipping logs to a central system.

    Why this is correct

    TLS (Transport Layer Security) encrypts log data in transit between the node's log collector and the central aggregation system, providing confidentiality by preventing eavesdropping and integrity via message authentication codes that detect tampering. Without TLS, logs sent over the network could be intercepted or modified by an attacker positioned on the network path, undermining the reliability of audit trails and forensic evidence. This practice directly addresses both confidentiality and integrity during the log transport phase.

  • ✗

    Set container 'stdout' logging only, avoiding file-based logs.

    Why it's wrong here

    Sending logs to stdout rather than files does not inherently protect their confidentiality or integrity; stdout is simply a stream captured by the container runtime and forwarded to the node's logging driver without encryption. File-based logs are not the vulnerability—the risk is that logs are stored or transmitted in plaintext and lack access controls, regardless of whether the source is stdout or a file. The container's output is only as secure as the infrastructure that captures and stores it, so avoiding file logs does nothing to prevent unauthorized reading or alteration.

  • ✓

    Store logs in a backend that supports encryption at rest (e.g., S3 with SSE).

    Why this is correct

    Encryption at rest, such as S3 Server-Side Encryption (SSE), ensures that log data stored on disk or object storage is unreadable if the underlying storage medium is compromised, protecting the confidentiality of historical logs. This practice is essential for meeting compliance requirements and reduces the impact of physical theft or unauthorized access to storage buckets. While it does not directly detect tampering during log generation, it prevents adversaries from extracting sensitive information from stored logs without the encryption keys.

  • ✓

    Run log collectors in a dedicated namespace with network policies limiting access.

    Why this is correct

    Running log collectors in a dedicated namespace and enforcing NetworkPolicies restricts both cluster-internal and external access to the collectors, limiting who can connect to the log ingestion endpoint. This isolation reduces the attack surface for unauthorized parties attempting to read logs or inject false log entries, thereby safeguarding both confidentiality and integrity. Network policy also helps ensure that only designated workloads can send logs, preventing rogue containers from corrupting the central log stream.

  • ✗

    Disable log rotation to prevent log tampering during rotation.

    Why it's wrong here

    Disabling log rotation does not prevent log tampering; in fact, it increases risk because logs grow unbounded, exhausting disk space and causing the container runtime or node to crash, which can lead to data loss and gaps in audit history. An attacker could still modify an active log file, and without rotation, there are no historical copies to compare changes against, making tampering harder to detect. Rotation is a lifecycle management technique to control file sizes and preserve logs; protecting integrity requires access controls, integrity monitoring, and secure storage, not disabling rotation.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.