
Certified Kubernetes Application Developer (CKAD)
Domain 4Objective 2
Kubernetes Security CKAD Practice Questions (Page 3)
Part of the Application Environment, Configuration and Security domain, which accounts for 25% of the CKAD exam. Linux Foundation does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 3–5 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
12concepts
25%of the exam
Questions 11–15
- 11
Which authorization mode uses attributes like user, group, and resource to make allow/deny decisions?
Select an answer first - 12
In a NetworkPolicy ingress rule, which field allows you to specify allowed source IP ranges?
Select an answer first - 13
What is the primary purpose of a ServiceAccount in Kubernetes?
Select an answer first - 14
A developer wants a Pod to authenticate to the Kubernetes API server using its ServiceAccount token. Which statement correctly describes how the ServiceAccount token is provided to the Pod by default?
Select an answer first - 15
At what point in the API request lifecycle do admission controllers run?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “CKAD” is a trademark of its owner, used for identification only.