Exam Details

  • Exam Code
    :CKS
  • Exam Name
    :Certified Kubernetes Security Specialist (CKS) Exam
  • Certification
    :Kubernetes System Administration
  • Vendor
    :Linux Foundation
  • Total Questions
    :46 Q&As
  • Last Updated
    :May 14, 2024

Linux Foundation Kubernetes System Administration CKS Questions & Answers

  • Question 41:

    CORRECT TEXT

    Context

    This cluster uses containerd as CRI runtime.

    Containerd's default runtime handler is runc. Containerd has been prepared to support an additional runtime handler, runsc (gVisor).

    Task

    Create a RuntimeClass named sandboxed using the prepared runtime handler named runsc.

    Update all Pods in the namespace server to run on gVisor.

    A. See the explanation below

    B. PlaceHolder

  • Question 42:

    CORRECT TEXT Context

    A default-deny NetworkPolicy avoids to accidentally expose a Pod in a namespace that doesn't have any other NetworkPolicy defined.

    Task

    Create a new default-deny NetworkPolicy named defaultdeny in the namespace testing for all traffic of type Egress.

    The new NetworkPolicy must deny all Egress traffic in the namespace testing.

    Apply the newly created default-deny NetworkPolicy to all Pods running in namespace testing.

    A. See explanation below.

    B. PlaceHolder

  • Question 43:

    Create a RuntimeClass named gvisor-rc using the prepared runtime handler named runsc.

    Create a Pods of image Nginx in the Namespace server to run on the gVisor runtime class

    A. See the explanation below:

    B. PlaceHolder

  • Question 44:

    CORRECT TEXT

    Task

    Create a NetworkPolicy named pod-access to restrict access to Pod users-service running in namespace dev-team. Only allow the following Pods to connect to Pod users-service:

    1.

    Pods in the namespace qa

    2.

    Pods with label environment: testing, in any namespace

    A. See explanation below.

    B. PlaceHolder

  • Question 45:

    Enable audit logs in the cluster, To Do so, enable the log backend, and ensure that

    1.

    logs are stored at /var/log/kubernetes-logs.txt.

    2.

    Log files are retained for 12 days.

    3.

    at maximum, a number of 8 old audit logs files are retained.

    4.

    set the maximum size before getting rotated to 200MB

    Edit and extend the basic policy to log:

    1.

    namespaces changes at RequestResponse

    2.

    Log the request body of secrets changes in the namespace kube-system.

    3.

    Log all other resources in core and extensions at the Request level.

    4.

    Log "pods/portforward", "services/proxy" at Metadata level.

    5.

    Omit the Stage RequestReceived

    All other requests at the Metadata level

    A. See the explanation below:

    B. PlaceHolder

  • Question 46:

    A container image scanner is set up on the cluster.

    Given an incomplete configuration in the directory

    /etc/kubernetes/confcontrol and a functional container image scanner with HTTPS endpoint https://test-server.local.8081/image_policy

    1.

    Enable the admission plugin.

    2.

    Validate the control configuration and change it to implicit deny.

    Finally, test the configuration by deploying the pod having the image tag as latest.

    A. See explanation below.

    B. PlaceHolder

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Linux Foundation exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CKS exam preparations and Linux Foundation certification application, do not hesitate to visit our Vcedump.com to find your solutions here.