CKS Practice Exam 02

A second independent CKS-style practice exam with 20 Kubernetes security challenges covering the public CKS domains through different operational security scenarios.

KubernetesCKS Training

Introduction

CKS Practice Exam 02 is a second, self-contained hands-on assessment for applying Kubernetes security skills under time pressure. It contains 20 independent challenges across six CKS-aligned domains, with a recommended total duration of 120 minutes. Each task is worth 5 points, and 67 points is the simulated LabEx passing threshold.

This exam form emphasizes different operational scenarios from Practice Exam 01: metadata-style egress protection, constrained API proxy permissions, host-service and log-access hardening, trusted-registry admission, offline release-signature verification, clean container builds, Helm output analysis, and incident containment. You must reach and prove the required final state in each fresh environment without a guided solution path.

What You Will Learn

  • Build precise egress policies that preserve DNS and approved services while blocking metadata-like, tenant, or suspicious endpoints
  • Replace wildcard or leaked-identity access with narrowly scoped RBAC and safer ServiceAccount token behavior
  • Reduce host attack surface by disabling a dedicated debug service and enforcing least-privilege log access
  • Apply Pod Security boundaries, rotate exposed Secrets, and replace unsafe hostPath storage
  • Enforce approved image registries with native admission policy and verify an offline signed release before deployment
  • Remove build credentials from runtime images and remediate Helm-rendered manifests using KubeLinter
  • Correlate bounded audit, workload, and runtime evidence to restore policy and contain compromised activity

Who This Course Is For

This course is for Kubernetes administrators, platform engineers, and security practitioners who want another full CKS-style practice form or a demanding check of their independent remediation skills. It assumes you can diagnose live Kubernetes and Linux state without step-by-step instructions.

Prerequisites: CKA-level Kubernetes administration, including confident use of kubectl, YAML, workloads, networking, RBAC, ServiceAccounts, and basic Linux service and file-permission commands. Completing Practice Exam 01 or any specific LabEx CKA course is not required.

Learning environment: Twenty isolated browser-accessible Ubuntu 22.04 VMs, each with a prepared single-node Kubernetes v1.34 environment. Task-specific manifests, certificates, findings, signatures, public keys, Helm charts, scanner data, checksums, audit extracts, and local images are staged inside the relevant VM; no external registry or production incident source is needed.

Frequently Asked Questions

Is Practice Exam 02 a continuation of Practice Exam 01?

No. It is an independent full practice form covering the same broad security domains through different scenarios. You can take either exam first, and no state or files are shared between them.

Is this an official CKS examination?

No. It is an independent LabEx learning resource. The 120-minute recommendation, 100-point scale, and 67-point threshold are simulated practice settings and do not produce an official certification result.

Does the course use real admission, host, and runtime controls?

Yes. You work with live RBAC, NetworkPolicy, Pod Security admission, ValidatingAdmissionPolicy, systemd state, Linux permissions, and running workloads. Risky external dependencies are replaced with controlled local endpoints, prepared artifacts, and bounded audit evidence.

Will I need internet access for registries, signatures, or scanners?

No. Approved images are local or cached, signature material is staged for offline verification, and Helm/KubeLinter inputs are supplied in the VM. The trusted-registry task tests policy decisions with server-side dry runs rather than requiring remote pulls.

Teacher

labby
Labby
Labby is the LabEx teacher.

Recommended For You

no data