Labour Day - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpm65

CKS Certified Kubernetes Security Specialist (CKS) Questions and Answers

Questions 4

CKS Question 4

Context

AppArmor is enabled on the cluster's worker node. An AppArmor profile is prepared, but not enforced yet.

CKS Question 4

Task

On the cluster's worker node, enforce the prepared AppArmor profile located at /etc/apparmor.d/nginx_apparmor.

Edit the prepared manifest file located at /home/candidate/KSSH00401/nginx-pod.yaml to apply the AppArmor profile.

Finally, apply the manifest file and create the Pod specified in it.

Options:

Buy Now
Questions 5

CKS Question 5

Context

A Role bound to a Pod's ServiceAccount grants overly permissive permissions. Complete the following tasks to reduce the set of permissions.

Task

Given an existing Pod named web-pod running in the namespace security.

Edit the existing Role bound to the Pod's ServiceAccount sa-dev-1 to only allow performing watch operations, only on resources of type services.

Create a new Role named role-2 in the namespace security, which only allows performing update

operations, only on resources of type namespaces.

Create a new RoleBinding named role-2-binding binding the newly created Role to the Pod's ServiceAccount.

CKS Question 5

Options:

Buy Now
Questions 6

 Fix all issues via configuration and restart the affected components to ensure the new setting takes effect.

 Fix all of the following violations that were found against the API server:-

      

  •  a. Ensure the --authorization-mode argument includes RBAC
  •   b. Ensure the --authorization-mode argument includes Node
  •   c. Ensure that the --profiling argument is set to false

Fix all of the following violations that were found against the Kubelet:-

   

  •   a. Ensure the --anonymous-auth argument is set to false.
  •  b. Ensure that the --authorization-mode argument is set to Webhook.

Fix all of the following violations that were found against the ETCD:-

      a. Ensure that the --auto-tls argument is not set to true

    Hint: Take the use of Tool Kube-Bench

Options:

Buy Now
Questions 7

CKS Question 7

Context

A CIS Benchmark tool was run against the kubeadm-created cluster and found multiple issues that must be addressed immediately.

Task

Fix all issues via configuration and restart the affected components to ensure the new settings take effect.

Fix all of the following violations that were found against the API server:

CKS Question 7

Fix all of the following violations that were found against the Kubelet:

CKS Question 7

CKS Question 7

Fix all of the following violations that were found against etcd:

CKS Question 7

Options:

Buy Now
Exam Code: CKS
Exam Name: Certified Kubernetes Security Specialist (CKS)
Last Update: Apr 25, 2024
Questions: 48

PDF + Testing Engine

$56  $159.99

Testing Engine

$42  $119.99
buy now CKS testing engine

PDF (Q&A)

$35  $99.99
buy now CKS pdf
dumpsmate guaranteed to pass
24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 28 Apr 2024