CKS Practice Exam 01 is a hands-on assessment for practicing Kubernetes security under exam-style constraints. You will solve 20 independent challenges across six CKS-aligned domains, with a recommended total duration of 120 minutes. Each challenge is worth 5 points, and 67 points is the simulated LabEx passing threshold.
Rather than following guided instructions, you will inspect live cluster state, repair manifests and access controls, harden workloads and host-level profiles, validate staged supply-chain evidence, and investigate bounded security events. Every challenge starts in a separate Ubuntu 22.04 VM with a single-node Kubernetes v1.34 environment, so changes and artifacts do not carry between tasks.
What You Will Learn
- Restrict workload traffic with precise NetworkPolicy selectors and publish a service through TLS Ingress
- Reduce excessive Kubernetes permissions with namespace-scoped RBAC and controlled ServiceAccount token mounting
- Install and apply local AppArmor and seccomp profiles while preserving workload availability
- Enforce Restricted Pod Security, non-root execution, immutable filesystems, and safer multi-container boundaries
- Protect Secret data through selective projected files and controlled file permissions
- Validate local images, checksums, SBOM metadata, approved digests, and KubeLinter findings before deployment
- Analyze bounded audit records and live container processes to identify, contain, and document suspicious activity
Who This Course Is For
This course is for Kubernetes administrators, platform engineers, and security practitioners preparing for performance-based CKS work or testing their ability to secure a cluster without step-by-step guidance. It is best suited to learners who can already inspect and modify Kubernetes resources confidently.
Prerequisites: CKA-level Kubernetes administration skills, including comfortable use of kubectl, YAML manifests, Pods, Deployments, Services, namespaces, RBAC, and basic Linux commands. No prior LabEx CKA course artifacts are required.
Learning environment: Twenty separate browser-accessible Ubuntu 22.04 virtual machines, each running a prepared single-node Kubernetes v1.34 environment. Required images, manifests, certificates, profiles, checksums, SBOM data, scanner output, and audit extracts are provided locally when a task needs them; no external registry or production incident data is required.
Frequently Asked Questions
Is this an official CKS exam or an exact copy of it?
No. It is an independent LabEx practice resource organized around CKS-aligned security domains. The 120-minute recommendation, 100-point scale, and 67-point threshold simulate exam practice and do not produce an official CKS result.
Are the challenges guided, and does one challenge depend on another?
The challenges are outcome-based rather than guided walkthroughs. Each opens in a fresh VM, so Kubernetes objects, host profiles, images, evidence files, and fixes from one challenge are unavailable in the next.
Will I work with real security controls or only read configuration examples?
You will change and validate live Kubernetes resources and runtime settings, including RBAC, NetworkPolicy, Pod security controls, AppArmor, seccomp, and read-only filesystems. Supply-chain and investigation tasks use deliberately staged local artifacts and bounded audit evidence so the work remains reproducible.
Do I need CKA certification before taking this course?
The course does not verify certification status, but its tasks assume CKA-level administration ability. The official CKS certification has its own CKA prerequisite; this independent practice course can be used whenever you have the required skills.



