CKS Monitoring, Logging and Runtime Security Practice Question
You suspect a container has been compromised. You want to preserve the container's filesystem for forensic analysis before terminating the pod. Which approach should you use?
⚠ Common exam trap
CKS often tests the misconception that deleting the pod or restarting the kubelet is a quick fix, but it destroys evidence needed for forensic analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use kubectl cp to copy files from the container to a safe location
Using kubectl cp to copy files from the container to a safe location preserves the container's filesystem for forensic analysis without altering the running container. This method allows you to extract files for offline analysis while keeping the container intact for further investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exec into the container and delete suspicious files
Why it's wrong here
Executing into the container to delete suspicious files is a forensic anti-pattern: it modifies the very filesystem you are trying to investigate, destroying timestamps, metadata, and potentially overwriting unallocated space with new inode writes. It also alerts the attacker that you know they are present, giving them a chance to cover their tracks or escalate before you can complete a proper evidence capture. Acquiring data must always precede any corrective action.
- ✗
Restart the kubelet on the node
Why it's wrong here
Restarting the kubelet is not a containment measure for a single compromised container; kubelet is the node agent that reconciles pod state, and restarting it can actually recreate the compromised pod if it is managed by a Deployment, or at minimum leave the container running while the node agent churns. It also does nothing to preserve the container's filesystem or memory state, and may trigger other side effects such as kubelet cache resets or pod recreations that destroy logs and runtime artifacts. Proper response is to isolate the workload and image the container data, not to bounce a node-level service.
- ✓
Use kubectl cp to copy files from the container to a safe location
Why this is correct
Using kubectl cp is correct because it reads the container's filesystem through the container runtime and produces a tar archive in a safe location without modifying the source files; the command uses tar and writes to stdout, so the container's storage layer is left untouched for subsequent analysis. This preserves evidence such as dropped payloads, shell history, modified binaries, and configuration files, and it can be performed quickly even while the container remains running. Be aware that kubectl cp does not capture memory or /proc, but for filesystem artifacts it is the advisable first step before any destructive containment.
- ✗
Immediately delete the pod to stop the attack
Why it's wrong here
Immediately deleting the pod to stop the attack destroys the container's writable layer, which contains the primary evidence — attacker-created files, reverse-shell binaries, logs, and command history — while also terminating network connections that could be monitored or traced. Even if the pod is recreated by a ReplicaSet or Deployment, the original container's runtime state (including its overlay filesystem changes and memory) is gone forever, making post-incident root-cause analysis impossible. The correct sequence is to preserve evidence first, and only then delete or isolate the pod after the filesystem has been captured.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.