
CrowdStrikeCertified Cloud Specialist (CCCS)
Domain 3Objective 3
3.3 Given a Use Case, Recommend a Kubernetes Admission Controller Policy Configuration CCCS Practice Questions (Page 2)
Part of the Cloud Security Policies and Rules domain, which makes up ~11% of our current practice bank.
20questions here
4free pages
7concepts
Questions 6–10
- 6
What is the key difference between mutating and validating admission controllers?
Select an answer first - 7
A development team wants to ensure that all pods in their namespace have a specific annotation for compliance tracking. They want the annotation to be added automatically if it is missing, but they do not want the pod to be rejected if the annotation is present. Which Kyverno policy rule should they use?
Select an answer first - 8
What is the relationship between a Constraint and a ConstraintTemplate in OPA/Gatekeeper?
Select an answer first - 9
A company is standardizing on a single policy engine for all Kubernetes clusters. They have three requirements: (1) validate that all images come from an approved registry, (2) mutate pods to add a default label, and (3) generate a ConfigMap when a new Namespace is created. Which policy engine should they choose?
Select an answer first - 10
A platform team is rolling out a new OPA Gatekeeper policy that will deny any pod that does not have a resource limit set. They have already applied the Constraint with enforcementAction set to 'dryrun' and reviewed the audit results. They now want to enforce the policy, but they are concerned about the impact on a critical application that has a few pods without resource limits. What should they do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.