Back to Mock exams
Mock Exam

CKS — Beyond Exam

The hardest security tier: lock a namespace end to end in three fused tasks — enforce/audit/warn Pod Security plus least-privilege identity, a workload hardened on every axis and consuming a secret safely, then full ingress AND egress isolation. Stricter than the exam or killer.sh. Pass mark 75%.

Your mission

The hardest security tier, above the drills and simulators. Three tasks, each fusing several CKS controls with no margin for a missed field. You'll take the vault namespace from open to airtight: Pod Security in all three modes plus least-privilege identity, a workload hardened on every axis that consumes a secret safely, and full ingress and egress isolation. Pass mark 75%; hints locked while the clock runs.

kubectl config set-context --current --namespace=vault

Skills you'll put into practice

cksapexsecurity