GoShiken は CKS 試験「Certified Kubernetes Security Specialist (CKS)」のサンプル問題を無料で提供しています。購入する前、弊社の模擬試験画面や問題のクオリティー、使いやすさを事前に体験できます。
Certified Kubernetes Security Specialist (CKS): CKS 試験
「Certified Kubernetes Security Specialist (CKS)」、CKS試験であります、Linux Foundation認定でございます。 最適な問題と解答をまとめられて、GoShiken はお客様のCKS試験に計 66 問をまとめてご用意いたしました。CKS試験の集結内容には、Kubernetes Security Specialist認定にあるエリアとカテゴリの全てをカバーしており、お客様の Certified Kubernetes Security Specialist (CKS) 試験認定合格の準備を手助けをお届けします。
リアルなCKSテストエンジン
弊社のCertified Kubernetes Security Specialist (CKS)受験資料はお客様がLinux Foundation CKS試験を受けるために必要なすべてのものが含まれています。詳細はCertified Kubernetes Security Specialist (CKS)認証専門家側が研究して制作されて、彼らは業界の経験を利用して正確で論理的な制品を改良され続けています。
品質と価値のあるCKS試験問題
GoShiken練習試験Linux Foundation CKSは認定された対象分野の専門家と公開された作成者のみを招いて、最高水準の技術的精度で作成されています。
CKS試験合格を100%返金保証
お客様がもしGoShikenのテストエンジンを使って CKS 試験「Certified Kubernetes Security Specialist (CKS)」に不合格されました場合、弊社はお客様に購入金額を全額返金致します。
- CKS 試験に関する広範囲的な問題と解答
- CKS 試験問題集は事前使用できる
- 問題は業界の専門家によって調査されて、ほぼ100%正解率の検証済みの回答
- CKS 試験問題集は定期的に更新されます
- 本番試験を基づいてまとめられた CKS 問題集
- こちらの問題集は販売される前に複数回シミュレーション済み
- GoShiken で購入すると決める前に、無料で CKS 試験問題集のサンプルを試せます
365日無料アップデート
購入日から365日無料アップデートをご利用いただけます。365日後、CKS問題集更新版がほしく続けて50%の割引を与えれます。
インスタントダウンロード
お支払い後、弊社のシステムは、1分以内に購入したCKS問題集をあなたのメールボックスにお送りします。 2時間以内に届かない場合に、お問い合わせください。
100%返金保証
購入後60日以内に、CKS試験に合格しなかった場合は、全額返金します。 そして、無料で他の試験問題集を入手できます。
IT分野での実力を示す指標として、Linux Foundation Certified Kubernetes Security Specialist (CKS)は多くの企業から評価されている認定資格です。GoShikenのCKS練習問題66問は、公式の出題範囲に基づいて作成されています。
Linux Foundation CKS 試験概要:
| 認定ベンダー: | Linux Foundation |
|---|---|
| 試験名: | Certified Kubernetes Security Specialist (CKS) Exam |
| 試験番号: | CKS |
| 出題数: | 実技タスク(問題数は固定されていません) |
| 受験料: | USD 395 |
| 認定の有効期間: | 2年間 |
| 試験時間: | 120 分 |
| 合格点: | 非公開 |
| 関連資格: | Certified Kubernetes Administrator (CKA) Certified Kubernetes Application Developer (CKAD) |
| 試験形式: | ハンズオンラボ(Kubernetes環境), ターミナルベースのタスク, 実技試験 |
| 対応言語: | 英語 |
| 推奨トレーニング: | Kubernetes Security Essentials (Linux Foundation トレーニング) CKS試験準備コース |
| 受験申し込み: | Linux Foundation 受験者ハンドブック Linux Foundation 認定ページ |
| サンプル問題: | Linux Foundation CKS サンプル問題 |
| 受験方法: | オンライン、プロクター(試験監督)付き、リモート実技試験 |
| 前提条件: | 有効なCertified Kubernetes Administrator (CKA)資格の保有が必須 |
| 公式シラバスのURL: | https://training.linuxfoundation.org/certification/certified-kubernetes-security-specialist/ |
Linux Foundation CKS 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| サプライチェーンのセキュリティ | 20% | - セキュアなCI/CDプラクティス - イメージのスキャンと検証 |
| クラスターのセットアップ | 15% | - クラスターコンポーネントの堅牢化 - セキュアなインストール設定 |
| マイクロサービスの脆弱性の最小化 | 20% | - Podセキュリティ基準 - コンテナの分離とセキュリティコンテキスト |
| クラスターの堅牢化 | 15% | - 認証と認可 - APIサーバーのセキュリティ |
| 監視、ロギング、およびランタイムセキュリティ | 15% | - 監査ロギングと監視 - ランタイム脅威検出 |
| システムの堅牢化 | 15% | - ホストのセキュリティ制御 - カーネルおよびノードのセキュリティ設定 |
CKS受験者からよく寄せられる質問
CKS(Certified Kubernetes Security Specialist (CKS) Exam)は、Linux Foundationが提供する認定試験で、合格すると「Certified Kubernetes Security Specialist (CKS)」の認定を取得できます。この認定はプロフェッショナルレベルに位置づけられています。関連する認定にはCertified Kubernetes Administrator (CKA)、Certified Kubernetes Application Developer (CKAD)などがあり、あわせて取得を目指す方も少なくありません。出題範囲の詳細は、このページの試験情報とGoShikenの練習問題でご確認いただけます。
CKS試験の出題数は実技タスク(問題数は固定されていません)、試験時間は120 分です。問題数から逆算すると1問にかけられる時間は限られるため、知識を問う問題は即答し、シナリオ問題に時間を残すペース配分を意識しましょう。見直しの時間を確保するためにも、GoShikenのテストエンジンで本番と同じ制限時間の模擬試験を繰り返し、時間切れを防ぐ感覚をつかんでおくことをおすすめします。
CKS試験の合格点は非公開、受験料はUSD 395です。不合格となった場合、再受験には改めて全額の受験料が必要になります。金銭的な負担を増やさないためにも、受験前にGoShikenの66問の練習問題で自己採点を行い、安定して合格点を上回れる状態になってから本番に臨みましょう。
CKS試験の受験条件は次のとおりです。有効なCertified Kubernetes Administrator (CKA)資格の保有が必須 受験条件は変更される場合があるため、最新情報は公式の試験案内ページで必ずご確認ください。
CKS試験は、以下の窓口からお申し込みいただけます。
受験方式はオンライン、プロクター(試験監督)付き、リモート実技試験となっています。申し込み手順や受験日の詳細は、各窓口の案内をご確認ください。
Linux Foundationは、CKS試験の対策として次の公式トレーニングを推奨しています。
公式トレーニングで基礎を固めたうえで、GoShikenの66問の練習問題でアウトプットを重ねると、知識の定着を効率的に確認できます。
はい、GoShikenではCKS対策の無料サンプル(PDFデモ)をご用意しています。実際の問題形式や解答の質をご確認いただいてからご購入いただけるため安心です。また、ご購入後は365日間、最新版への無料更新をご利用いただけます。365日を過ぎた後も更新サービスを50%割引で継続できますので、長期間にわたって最新の出題傾向に対応した教材をご活用いただけます。
GoShikenでは返金保証をご用意しています。ご購入後60日以内に対応する試験を受験し、残念ながら不合格となった場合は、受験票の写しと公式スコアレポート(Score Report)のPDFを試験後2日以内にご提出いただくことで、7日以内に全額を返金いたします。ただし、購入後3日以内の受験(学習期間が短すぎるため)、ダウンロードのみで未受験の場合、無料資料および期限切れのご注文は対象外です。また、受験者名とお支払い者名が一致している必要があります。返金の代わりに製品交換をご希望の場合は、同等の試験対策資料2点を無料でご提供し、ご購入済み製品の更新サービスもそのままご利用いただけます。納品は、お支払い完了後すぐにダウンロードできるほか、1分以内にご登録のメールアドレスへもお届けします。2時間経っても届かない場合はカスタマーサポートまでご連絡ください。インストールするパソコンの台数に制限はありませんので、ご自宅と職場など複数の環境で学習を進められます。
CKS試験の出題範囲は、全部で6つの分野で構成されています。主な分野としては、「マイクロサービスの脆弱性の最小化」(20%)、「サプライチェーンのセキュリティ」(20%)、「監視、ロギング、およびランタイムセキュリティ」(15%)などが挙げられます。各分野に含まれる具体的なトピックは、このページ上部の出題範囲に一覧で掲載していますので、学習計画を立てる際にご活用ください。
Linux Foundation Certified Kubernetes Security Specialist (CKS) 認定 CKS 試験問題:
SIMULATION
Create a PSP that will only allow the persistentvolumeclaim as the volume type in the namespace restricted.
Create a new PodSecurityPolicy named prevent-volume-policy which prevents the pods which is having different volumes mount apart from persistentvolumeclaim.
Create a new ServiceAccount named psp-sa in the namespace restricted.
Create a new ClusterRole named psp-role, which uses the newly created Pod Security Policy prevent-volume-policy Create a new ClusterRoleBinding named psp-role-binding, which binds the created ClusterRole psp-role to the created SA psp-sa.
Hint:
Also, Check the Configuration is working or not by trying to Mount a Secret in the pod maifest, it should get failed.
POD Manifest:
apiVersion: v1
kind: Pod
metadata:
name:
spec:
containers:
- name:
image:
volumeMounts:
- name:
mountPath:
volumes:
- name:
secret:
secretName:
正解:
See the Explanation belowExplanation:
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: restricted
annotations:
seccomp.security.alpha.kubernetes.io/allowedProfileNames: 'docker/default,runtime/default' apparmor.security.beta.kubernetes.io/allowedProfileNames: 'runtime/default' seccomp.security.alpha.kubernetes.io/defaultProfileName: 'runtime/default' apparmor.security.beta.kubernetes.io/defaultProfileName: 'runtime/default' spec:
privileged: false
# Required to prevent escalations to root.
allowPrivilegeEscalation: false
# This is redundant with non-root + disallow privilege escalation,
# but we can provide it for defense in depth.
requiredDropCapabilities:
- ALL
# Allow core volume types.
volumes:
- 'configMap'
- 'emptyDir'
- 'projected'
- 'secret'
- 'downwardAPI'
# Assume that persistentVolumes set up by the cluster admin are safe to use.
- 'persistentVolumeClaim'
hostNetwork: false
hostIPC: false
hostPID: false
runAsUser:
# Require the container to run without root privileges.
rule: 'MustRunAsNonRoot'
seLinux:
# This policy assumes the nodes are using AppArmor rather than SELinux.
rule: 'RunAsAny'
supplementalGroups:
rule: 'MustRunAs'
ranges:
# Forbid adding the root group.
- min: 1
max: 65535
fsGroup:
rule: 'MustRunAs'
ranges:
# Forbid adding the root group.
- min: 1
max: 65535
readOnlyRootFilesystem: false
SIMULATION
Context
For testing purposes, the kubeadm provisioned cluster 's API server
was configured to allow unauthenticated and unauthorized access.
Task
First, secure the cluster 's API server configuring it as follows:
. Forbid anonymous authentication
. Use authorization mode Node,RBAC
. Use admission controller NodeRestriction
The cluster uses the Docker Engine as its container runtime . If needed, use the docker command to troubleshoot running containers.
kubectl is configured to use unauthenticated and unauthorized access. You do not have to change it, but be aware that kubectl will stop working once you have secured the cluster .
You can use the cluster 's original kubectl configuration file located at etc/kubernetes/admin.conf to access the secured cluster.
Next, to clean up, remove the ClusterRoleBinding
system:anonymous.
正解:
See the Explanation below for complete solution
Explanation:
1) SSH to control-plane node
ssh cks000002
sudo -i
2) Edit API Server static pod manifest
API server in kubeadm runs as a static pod.
vi /etc/kubernetes/manifests/kube-apiserver.yaml
3) Apply required API Server security settings
3.1 Forbid anonymous authentication
Find command: section and ensure this line exists:
- --anonymous-auth=false
3.2 Use authorization mode Node,RBAC
Ensure exactly this line exists (and no AlwaysAllow):
- --authorization-mode=Node,RBAC
❌ Remove if present:
- --authorization-mode=AlwaysAllow
3.3 Enable admission controller NodeRestriction
Find --enable-admission-plugins and ensure NodeRestriction is included.
Correct example:
- --enable-admission-plugins=NodeRestriction
If other plugins already exist, append NodeRestriction, e.g.:
- --enable-admission-plugins=NamespaceLifecycle,ServiceAccount,NodeRestriction
4) Save file and let kubelet restart API server
Just save and exit (:wq)
Kubelet will automatically restart the API server pod.
5) Switch kubectl to secured config
Current kubectl will stop working after API server hardening.
export KUBECONFIG=/etc/kubernetes/admin.conf
Verify access:
kubectl get nodes
6) Remove insecure ClusterRoleBinding
Delete system:anonymous binding:
kubectl delete clusterrolebinding system:anonymous
Verify removal:
kubectl get clusterrolebinding | grep anonymous
(no output = correct)
7) Quick validation (optional but fast)
API server flags check:
grep -n "anonymous-auth" /etc/kubernetes/manifests/kube-apiserver.yaml
grep -n "authorization-mode" /etc/kubernetes/manifests/kube-apiserver.yaml grep -n "NodeRestriction" /etc/kubernetes/manifests/kube-apiserver.yaml
SIMULATION
Documentation
Deployment, Pod Security Admission, Pod Security Standards
You must connect to the correct host . Failure to do so may result in a zero score.
[candidate@base] $ ssh cks000036
Context
For compliance, all user namespaces enforce the restricted Pod Security Standard .
Task
The confidential namespace contains a Deployment that is not compliant with the restricted Pod Security Standard . Thus, its Pods can not be scheduled.
Modify the Deployment to be compliant and verify that the Pods are running.
The Deployment's manifest file can be found at /home/candidate/nginx-unprivileged.yaml.
正解:
See the Explanation below for complete solution
Explanation:
1) Connect to the correct host
ssh cks000036
sudo -i
export KUBECONFIG=/etc/kubernetes/admin.conf
2) Confirm the failing Pods + see the PSA error (fast)
kubectl -n confidential get deploy
kubectl -n confidential get pods
kubectl -n confidential describe deploy <deployment-name> | sed -n '/Events/,$p' (You'll usually see "violates PodSecurity 'restricted' ..." with the exact missing fields.)
3) Edit the provided manifest
vi /home/candidate/nginx-unprivileged.yaml
You must ensure the Pod template becomes compliant. Add/ensure the following exact blocks:
4) Add Pod-level securityContext (under spec.template.spec)
Find:
spec:
template:
spec:
Add this block under it (or merge if securityContext: already exists):
securityContext:
runAsNonRoot: true
runAsUser: 65535
seccompProfile:
type: RuntimeDefault
5) Add Container-level securityContext (under the nginx container)
Find:
containers:
- name: ...
image: ...
Under that container, add (or adjust) this exact block:
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
If there are multiple containers, apply the same container securityContext to each one.
Save and exit:
:wq
6) Apply the manifest to the confidential namespace
kubectl -n confidential apply -f /home/candidate/nginx-unprivileged.yaml Wait rollout:
kubectl -n confidential rollout status deployment/<deployment-name>
If you don't know the deployment name from the file, list:
kubectl -n confidential get deploy
7) Verify Pods are running
kubectl -n confidential get pods -o wide
If still failing, show the exact PSA violation (this tells you what else to fix):
kubectl -n confidential describe pod <pod-name> | sed -n '/Events/,$p'
Quick "if it still fails" fixes (common restricted blockers)
Open the manifest again and ensure these are NOT set (or are removed/false):
hostNetwork: true
hostPID: true
hostIPC: true
any hostPort:
privileged: true
capabilities.add:
seccompProfile: Unconfined
runAsUser: 0 or runAsNonRoot: false
Then re-apply.
Minimal compliant result (what the grader expects)
Your Pod template should include:
seccompProfile: RuntimeDefault
runAsNonRoot: true (and a non-root UID like 65535)
container: allowPrivilegeEscalation: false
container: capabilities.drop: [ALL]
container: readOnlyRootFilesystem: true
SIMULATION
Cluster: qa-cluster
Master node: master Worker node: worker1
You can switch the cluster/configuration context using the following command:
[desk@cli] $ kubectl config use-context qa-cluster
Task:
Create a NetworkPolicy named restricted-policy to restrict access to Pod product running in namespace dev.
Only allow the following Pods to connect to Pod products-service:
1. Pods in the namespace qa
2. Pods with label environment: stage, in any namespace
正解:
See the Explanation belowExplanation:



SIMULATION
Secrets stored in the etcd is not secure at rest, you can use the etcdctl command utility to find the secret value for e.g:- ETCDCTL_API=3 etcdctl get /registry/secrets/default/cks-secret --cacert="ca.crt" --cert="server.crt" --key="server.key" Output
Using the Encryption Configuration, Create the manifest, which secures the resource secrets using the provider AES-CBC and identity, to encrypt the secret-data at rest and ensure all secrets are encrypted with the new configuration.
正解:
See the Explanation belowExplanation:
ETCD secret encryption can be verified with the help of etcdctl command line utility.
ETCD secrets are stored at the path /registry/secrets/$namespace/$secret on the master node.
The below command can be used to verify if the particular ETCD secret is encrypted or not.
# ETCDCTL_API=3 etcdctl get /registry/secrets/default/secret1 [...] | hexdump -C
430 お客様のコメント最新のコメント 「一部の類似なコメント・古いコメントは隠されています」
あなたはCKS問題集を選択すれば、きっとCKS試験をパスできます。本当に有効的な資料です。
ここで感謝を申し上げます。ありがとうございました。高得点で合格しました。よく出題されるパターンを徹底分析した予想CKS問題集。
GoShikenさんの押さえるべきポイントを確実に覚えればなかなかCKS試験でいい点は取れると思う。
GoShikenの問題集は価格が安いのに電子版ももらえて素晴らしい。CKS試験用のテキストです。
本日CKS試験を受けました。合格できました。
購入した問題集の問題が多数出てました。本当に役に立ちました。
ありがとうございました。
本当にのCKSひとつしか読みませんでしたが、記載内容への理解を深めることで合格しました。Linux Foundationありがとう
ここGoShikenの出た試験対策問題集は解き方がよくわかる詳しい解説が好きです。CKSにみごと合格いたしました
間違い選択肢についても確認できる,詳細な解説だお気に入りです。サクサク答え合わせをしながら解き進めることができるので大変見やすく、使いやすいです
これから始めたい方にも良さそうです。また、資格勉強のためだけでなくCKSがどんなものか知りたい方にもおすすめできます。
間違い選択肢についても確認できる,詳細な解説だお気に入りです。サクサク答え合わせをしながら解き進めることができるので大変見やすく、使いやすいです
Linux Foundationの問題集は実に素晴らしい。
読みやすく わかりやすい解説
これでCKS試験に受かる気がした。
これまで行われた答練の中から本試験と遜色のないCKS問題集ですね!これを勉強させて無事合格です!GoShikenさん最高です
できるだけラクにCKS合格したいんで、ともだちの紹介でGoShikenサイトのこと知って買って合格っす。簡単っす。
CKS試験問題集はいい資料ですので、私はCKS試験問題集を選びました。もちろん、CKS試験に合格しました。
問題集は価格が安いのに電子版ももらえて素晴らしい。CKS試験用のテキストです。演習問題を掲載しているので本番でも動じない実力を養うことができます。
