
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 6Objective 4
Access to Sensitive Data KCSA Practice Questions (Page 1)
Part of the Kubernetes Threat Model domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
6concepts
16%of the exam
Questions 1–5
- 1
Where are Kubernetes Secrets stored in etcd by default?
Select an answer first - 2
A security team is designing a defense-in-depth strategy to protect secrets in a Kubernetes cluster. They want to ensure that even if the API server is compromised, secrets are not exposed. Which combination of controls is MOST effective?
Select an answer first - 3
Which of the following is a recommended mitigation strategy for protecting sensitive data in Kubernetes?
Select an answer first - 4
A security analyst is tracing a potential data exfiltration path in a Kubernetes cluster. They find that a pod has access to a Secret that contains a database password. The pod is compromised. Which of the following is the MOST likely path the attacker would use to exfiltrate the data?
Select an answer first - 5
Which type of threat actor is characterized by having legitimate access to the cluster but misusing it?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.