CKS ソフト版
- インストール可能なソフトウェア応用
- 本番の試験環境をシミュレート
- 人にCKS試験の自信をもたせる
- MSシステムをサポート
- 練習用の2つモード
- いつでもオフラインで練習
- ソフト版キャプチャーをチェックする
- 問題と解答: 66
- 最近更新時間: 2026-09-18
- 価格: ¥7500
CKS オンライン版
- 学習を簡単に、便利オンラインツール
- インスタントオンラインアクセス
- すべてのWebブラウザをサポート
- いつでもオンラインで練習
- テスト履歴と性能レビュー
- Windows/Mac/Android/iOSなどをサポート
- オンラインテストエンジンを試用する
- 問題と解答: 66
- 最近更新時間: 2026-09-18
- 価格: ¥7500
CKS PDF版
- 印刷可能なCKS PDF版
- Linux Foundation専門家による準備
- インスタントダウンロード
- いつでもどこでも勉強
- 365日無料アップデート
- CKS無料PDFデモをご利用
- PDF版試用をダウンロードする
- 問題と解答: 66
- 最近更新時間: 2026-09-18
- 価格: ¥7500
CKS試験の本番では、限られた時間内に問題を解き切る時間配分の感覚も問われます。PassTestのDesktop Test EngineならLinux Foundation Certified Kubernetes Security Specialist (CKS)の本番環境を再現した模擬試験に取り組めるため、当日の緊張を和らげる練習ができます。
Linux Foundation CKS 試験概要:
| 認定ベンダー: | Linux Foundation |
|---|---|
| 試験名: | Certified Kubernetes Security Specialist (CKS) Exam |
| 試験番号: | CKS |
| 出題数: | 実技タスク(問題数は固定されていません) |
| 試験時間: | 120 分 |
| 対応言語: | 英語 |
| 関連資格: | Certified Kubernetes Administrator (CKA) Certified Kubernetes Application Developer (CKAD) |
| 受験料: | USD 395 |
| 合格点: | 非公開 |
| 試験形式: | ハンズオンラボ(Kubernetes環境), ターミナルベースのタスク, 実技試験 |
| 認定の有効期間: | 2年間 |
| 推奨トレーニング: | CKS試験準備コース Kubernetes Security Essentials (Linux Foundation トレーニング) |
| 受験申し込み: | Linux Foundation 受験者ハンドブック Linux Foundation 認定ページ |
| サンプル問題: | Linux Foundation CKS サンプル問題 |
| 受験方法: | オンライン、プロクター(試験監督)付き、リモート実技試験 |
| 前提条件: | 有効なCertified Kubernetes Administrator (CKA)資格の保有が必須 |
| 公式シラバスのURL: | https://training.linuxfoundation.org/certification/certified-kubernetes-security-specialist/ |
Linux Foundation CKS 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| トピック 1: マイクロサービスの脆弱性の最小化 | 20% | - コンテナの分離とセキュリティコンテキスト - Podセキュリティ基準 |
| トピック 2: クラスターのセットアップ | 15% | - セキュアなインストール設定 - クラスターコンポーネントの堅牢化 |
| トピック 3: システムの堅牢化 | 15% | - ホストのセキュリティ制御 - カーネルおよびノードのセキュリティ設定 |
| トピック 4: サプライチェーンのセキュリティ | 20% | - イメージのスキャンと検証 - セキュアなCI/CDプラクティス |
| トピック 5: 監視、ロギング、およびランタイムセキュリティ | 15% | - 監査ロギングと監視 - ランタイム脅威検出 |
| トピック 6: クラスターの堅牢化 | 15% | - APIサーバーのセキュリティ - 認証と認可 |
Linux Foundation Certified Kubernetes Security Specialist (CKS)の疑問にお答えします
CKSはLinux Foundationが実施する「Certified Kubernetes Security Specialist (CKS) Exam」の試験で、合格するとCertified Kubernetes Security Specialist (CKS)の認定資格を取得できます。この資格はLinux Foundationの認定体系においてプロフェッショナルに位置づけられています。関連する認定資格には、Certified Kubernetes Administrator (CKA)、Certified Kubernetes Application Developer (CKAD)などがあります。PassTestではこの試験に特化した66問の練習問題をご用意していますので、資格取得に向けた対策にぜひご活用ください。
Certified Kubernetes Security Specialist (CKS) Exam(CKS)の問題数は実技タスク(問題数は固定されていません)、試験時間は120 分です。限られた時間内にすべての問題を解き切るには、1問ごとの解答ペースを意識し、分からない問題に長時間とどまりすぎない時間配分が欠かせません。PassTestのDesktop Test EngineやOnline Test Engineで制限時間を設けた模擬試験に繰り返し取り組み、本番と同じ時間感覚を身につけておくことをおすすめします。
CKS試験の合格基準点は非公開で、受験料はUSD 395です。万が一不合格となった場合、再受験には改めて全額の受験料が必要になるため、本番を申し込む前にPassTestの練習問題で自己採点を繰り返し、安定して合格基準を上回れる状態になってから受験に臨むと安心です。
CKS試験の前提条件については、有効なCertified Kubernetes Administrator (CKA)資格の保有が必須と案内されています。受験条件は変更される場合もありますので、お申し込みの前に公式の試験案内で最新情報を必ずご確認ください。
CKS試験の申し込みは、以下の公式チャネルから行えます。
なお、試験方式はオンライン、プロクター(試験監督)付き、リモート実技試験となっています。
受験日程や会場の空き状況は、お申し込みの前に公式サイトでご確認ください。
Linux FoundationはCKS試験向けに、以下の公式推奨トレーニングを提供しています。
公式トレーニングで基礎知識を固めたうえで、PassTestの66問の練習問題でアウトプットを重ねれば、理解の定着と得点力の向上を効率よく両立できます。
はい、PassTestではCKS練習問題の無料サンプルをご用意しており、問題の品質や出題傾向を購入前に実際にご確認いただけます。ご購入後は365日間無料で更新版を受け取れ、無料期間の終了後も50%割引で更新サービスを継続いただけます。
PassTestでは「返金保証」をご用意しています。ご購入後60日以内にCKS試験を受験して不合格となった場合、受験票の写しと公式のScore ReportのPDFを試験後2日以内にご提出いただければ、内容を確認のうえ7日以内に全額返金いたします。なお、ご購入から3日以内の受験や、ダウンロード後に実際に受験されなかった場合、無料の資料および期限切れのご注文は対象外となり、受験者の氏名はお支払い時の名義と一致している必要があります。返金の代わりに、同等の試験対策資料2点を無料でお受け取りいただき、お持ちの製品の更新サービスを継続するご選択も可能です。製品はお支払い完了後1分以内にご登録のメールアドレスへお届けし、即時ダウンロードでご利用いただけます。2時間経っても届かない場合はカスタマーサポートまでご連絡ください。なお、インストール可能なパソコンの台数に制限はありません。
CKS試験の出題範囲は、公式の試験概要では6つの分野に分かれています。主な分野としては、「クラスターのセットアップ」(出題比率:15%)、「クラスターの堅牢化」(出題比率:15%)、「監視、ロギング、およびランタイムセキュリティ」(出題比率:15%)などが挙げられます。各分野に含まれる詳細なトピックと配点の内訳は、このページ上部の試験範囲一覧をご確認ください。
Linux Foundation Certified Kubernetes Security Specialist (CKS) 認定 CKS 試験問題:
SIMULATION
You must complete this task on the following cluster/nodes:
Cluster: trace
Master node: master
Worker node: worker1
You can switch the cluster/configuration context using the following command:
[desk@cli] $ kubectl config use-context trace
Given: You may use Sysdig or Falco documentation.
Task:
Use detection tools to detect anomalies like processes spawning and executing something weird frequently in the single container belonging to Pod tomcat.
Two tools are available to use:
1. falco
2. sysdig
Tools are pre-installed on the worker1 node only.
Analyse the container's behaviour for at least 40 seconds, using filters that detect newly spawning and executing processes.
Store an incident file at /home/cert_masters/report, in the following format:
[timestamp],[uid],[processName]
Note: Make sure to store incident file on the cluster's worker node, don't move it to master node.
正解:
See the Explanation below
Explanation:
$vim /etc/falco/falco_rules.local.yaml
- rule: Container Drift Detected (open+create)
desc: New executable created in a container due to open+create
condition: >
evt.type in (open,openat,creat) and
evt.is_open_exec=true and
container and
not runc_writing_exec_fifo and
not runc_writing_var_lib_docker and
not user_known_container_drift_activities and
evt.rawres>=0
output: >
%evt.time,%user.uid,%proc.name # Add this/Refer falco documentation
priority: ERROR
$kill -1 <PID of falco>
Explanation:
[desk@cli] $ ssh node01
[node01@cli] $ vim /etc/falco/falco_rules.yaml
search for Container Drift Detected & paste in falco_rules.local.yaml
[node01@cli] $ vim /etc/falco/falco_rules.local.yaml
- rule: Container Drift Detected (open+create)
desc: New executable created in a container due to open+create
condition: >
evt.type in (open,openat,creat) and
evt.is_open_exec=true and
container and
not runc_writing_exec_fifo and
not runc_writing_var_lib_docker and
not user_known_container_drift_activities and
evt.rawres>=0
output: >
%evt.time,%user.uid,%proc.name # Add this/Refer falco documentation
priority: ERROR
[node01@cli] $ vim /etc/falco/falco.yaml
SIMULATION
Context
AppArmor is enabled on the cluster's worker node. An AppArmor profile is prepared, but not enforced yet.
Task
On the cluster's worker node, enforce the prepared AppArmor profile located at /etc/apparmor.d/nginx_apparmor.
Edit the prepared manifest file located at /home/candidate/KSSH00401/nginx-pod.yaml to apply the AppArmor profile.
Finally, apply the manifest file and create the Pod specified in it.
正解:
See the Explanation belowExplanation:


SIMULATION
Context
For testing purposes, the kubeadm provisioned cluster 's API server
was configured to allow unauthenticated and unauthorized access.
Task
First, secure the cluster 's API server configuring it as follows:
. Forbid anonymous authentication
. Use authorization mode Node,RBAC
. Use admission controller NodeRestriction
The cluster uses the Docker Engine as its container runtime . If needed, use the docker command to troubleshoot running containers.
kubectl is configured to use unauthenticated and unauthorized access. You do not have to change it, but be aware that kubectl will stop working once you have secured the cluster .
You can use the cluster 's original kubectl configuration file located at etc/kubernetes/admin.conf to access the secured cluster.
Next, to clean up, remove the ClusterRoleBinding
system:anonymous.
正解:
See the Explanation below for complete solution
Explanation:
1) SSH to control-plane node
ssh cks000002
sudo -i
2) Edit API Server static pod manifest
API server in kubeadm runs as a static pod.
vi /etc/kubernetes/manifests/kube-apiserver.yaml
3) Apply required API Server security settings
3.1 Forbid anonymous authentication
Find command: section and ensure this line exists:
- --anonymous-auth=false
3.2 Use authorization mode Node,RBAC
Ensure exactly this line exists (and no AlwaysAllow):
- --authorization-mode=Node,RBAC
❌ Remove if present:
- --authorization-mode=AlwaysAllow
3.3 Enable admission controller NodeRestriction
Find --enable-admission-plugins and ensure NodeRestriction is included.
Correct example:
- --enable-admission-plugins=NodeRestriction
If other plugins already exist, append NodeRestriction, e.g.:
- --enable-admission-plugins=NamespaceLifecycle,ServiceAccount,NodeRestriction
4) Save file and let kubelet restart API server
Just save and exit (:wq)
Kubelet will automatically restart the API server pod.
5) Switch kubectl to secured config
Current kubectl will stop working after API server hardening.
export KUBECONFIG=/etc/kubernetes/admin.conf
Verify access:
kubectl get nodes
6) Remove insecure ClusterRoleBinding
Delete system:anonymous binding:
kubectl delete clusterrolebinding system:anonymous
Verify removal:
kubectl get clusterrolebinding | grep anonymous
(no output = correct)
7) Quick validation (optional but fast)
API server flags check:
grep -n "anonymous-auth" /etc/kubernetes/manifests/kube-apiserver.yaml
grep -n "authorization-mode" /etc/kubernetes/manifests/kube-apiserver.yaml grep -n "NodeRestriction" /etc/kubernetes/manifests/kube-apiserver.yaml
SIMULATION
Context:
Cluster: gvisor
Master node: master1
Worker node: worker1
You can switch the cluster/configuration context using the following command:
[desk@cli] $ kubectl config use-context gvisor
Context: This cluster has been prepared to support runtime handler, runsc as well as traditional one.
Task:
Create a RuntimeClass named not-trusted using the prepared runtime handler names runsc.
Update all Pods in the namespace server to run on newruntime.
正解:
See the Explanation below
Explanation:
Explanation:
[desk@cli] $vim runtime.yaml
apiVersion: node.k8s.io/v1
kind: RuntimeClass
metadata:
name: not-trusted
handler: runsc
[desk@cli] $ k apply -f runtime.yaml
[desk@cli] $ k get pods
NAME READY STATUS RESTARTS AGE
nginx-6798fc88e8-chp6r 1/1 Running 0 11m
nginx-6798fc88e8-fs53n 1/1 Running 0 11m
nginx-6798fc88e8-ndved 1/1 Running 0 11m
[desk@cli] $ k get deploy
NAME READY UP-TO-DATE AVAILABLE AGE
nginx 3/3 11 3 5m
[desk@cli] $ k edit deploy nginx
SIMULATION
Service is running on port 389 inside the system, find the process-id of the process, and stores the names of all the open-files inside the /candidate/KH77539/files.txt, and also delete the binary.
正解:
See the Explanation belowExplanation:
root# netstat -ltnup
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 127.0.0.1:17600 0.0.0.0:* LISTEN 1293/dropbox tcp 0 0 127.0.0.1:17603 0.0.0.0:* LISTEN 1293/dropbox tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 575/sshd tcp 0 0 127.0.0.1:9393 0.0.0.0:* LISTEN 900/perl tcp 0 0 :::80 :::* LISTEN 9583/docker-proxy tcp 0 0 :::443 :::* LISTEN 9571/docker-proxy udp 0 0 0.0.0.0:68 0.0.0.0:* 8822/dhcpcd
...
root# netstat -ltnup | grep ':22'
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 575/sshd
The ss command is the replacement of the netstat command.
Now let's see how to use the ss command to see which process is listening on port 22:
root# ss -ltnup 'sport = :22'
Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port
tcp LISTEN 0 128 0.0.0.0:22 0.0.0.0:* users:("sshd",pid=575,fd=3))
1250 お客様のコメント最新のコメント 「一部の類似なコメント・古いコメントは隠されています」
これCKS一冊あれば十分に事足りると私は思いました。わかりやすい!ありがとうございました。
PassTestさんの押さえるべきポイントを確実に覚えればなかなかCKS試験でいい点は取れると思う。
説明が非常に分かりやすくPassTestの問題集は、短時間内に受験したい人におすすめだな。すべての問題を暗記して言ったら絶対合格すると思うよ。だって試験問題のほとんどがこの問題集に収めたんだもん。
また機会があれば、宜しくお願い致します。やったー!暗記が苦手な私にとって、勉強はちょっと大変だと思います。
受験直前までの仕上げ学習をガッチリサポート! PassTestさんの問題集はCKSていねい&わかりやすい解説
もかなり高いですね。PassTestさんの問題集を購入するのはこれで四回目になりました。今回も無事合格です。
試験前もずっと勉強していたので、よかったです。PassTest参考書とあとは努力ですね。
PassTestさんまたお世話になりたいとおもいます。試験にある問題はほぼPassTestのこの問題集にもあって、短時間で答え終わって、今日結果がてて本当に合格になった。
CKS試験に合格した。しかも高得点。次はKCNAに挑戦したいと思います!
PassTestさん、お世話になりました。CKSは試験合格しました。
副手の要領は問題集を一通りやり、後は模擬問題をやることです。苦手なところは覚えるまでに繰り返し勉強するべきです。
すこしでもご参考になれば嬉しいです。
識もしっかりと身につくと思います。PassTestの商品はどれも優秀すぎます。私は1日4時間を3日で合格できました。
ネットから調べさせて、PassTestという素晴らしいサイトに出会いました。前回購入したKCNAもそうですけど、PassTestの問題集内容は超絶わかりやすくて受験するにピッタリな問題集だと思う。CKSに合格しました。また次回もここにお世話になりたいと思います。
合格しました。PassTestさんのおかげです
内容も濃く、問題や擬似問題集と回答などもあり、CKS1冊で試験に対応できる良い本だと思います。
PassTestさんの問題集の品質は最高すぎます。CKSに無事合格しました。ここで感謝致します。わかりやすかったですし、内容も全面的で。
素晴らしい問題集に出会いさせてもらったLinux Foundationに感謝しかないです。CKSにやっと再受験して合格だよ!!早速次に受験したいKCNAの問題集を購入させていただきました。今回もいい結果が出そう。
網羅性が高い。CKS素敵。
CKS試験のみを勉強した。今日、高い点数で試験に合格しました。頑張って!
Linux FoundationのCKS認証が昨日合格することができました。
PassTest様が提供した問題集はほぼ試験範囲を網羅しています。
実に役立ちました。ありがとうございました。
問題も解説も良質なので、たくさん問題を解いておきたい方にはおすすめできますね。
しかもCKS試験の問題にも入ていて、高得点で受かりました。
セキュリティ&プライバシー
我々は顧客のプライバシーを尊重する。McAfeeセキュリティサービスを使用して、お客様の個人情報および安心のために最大限のセキュリティを提供します。
365日無料アップデート
購入日から365日無料アップデートをご利用いただけます。365日後、更新版がほしく続けて50%の割引を与えれます。
返金保証
購入後60日以内に、試験に合格しなかった場合は、全額返金します。 そして、無料で他の製品を入手できます。
インスタントダウンロードCKS
お支払い後、弊社のシステムは、1分以内に購入した商品をあなたのメールボックスにお送りします。 2時間以内に届かない場合に、お問い合わせください。
関連製品
関するブログ
- [2026年更新]CKS.PDFの問題回答PDFサンプル問題現実的 [Q66-Q83]
- 2026年最新の100%試験高合格率CKS問題集PDF [Q75-Q99]
- CKS PDF問題集で2026年01月04日最近更新された問題 [Q70-Q86]
- 無料提供中のCKS試験問題集で(2025年最新のPDF問題集)信頼度の高いテストエンジン [Q29-Q51]
- [更新されたのは2025年]Linux Foundation CKS問題準備には無料サンプルのPDF [Q24-Q47]
- [2025年02月27日] 信頼され続けるCKS試験のコツがあるPDF試験材料 [Q25-Q49]
- 問題集は全額返金保証付きのCKS問題集最大50%オフ [Q18-Q34]
- [2024年11月21日] 365日更新、有効なCKS知能問題集 [Q25-Q49]
- リアルなCKS最新試験は2024年最新のCKS練習テスト問題集を提供しています [Q11-Q34]
- CKS PDF問題集で2024年01月14日試験問題 有効なCKS問題集 [Q26-Q43]

