
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 6Objective 4
Access to Sensitive Data KCSA Practice Questions (Page 3)
Part of the Kubernetes Threat Model domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
6concepts
16%of the exam
Questions 11–15
- 11
A security analyst is investigating an incident where an attacker accessed sensitive data in a Kubernetes cluster. The attacker used a valid service account token that was found in a pod's environment variables. The service account had permissions to read Secrets in the same namespace. Which of the following is the MOST likely attack vector?
Select an answer first - 12
A Kubernetes cluster stores TLS certificates as Secrets. An attacker gains read access to these Secrets and uses them to impersonate the service. What is the MOST likely impact?
Select an answer first - 13
A security analyst is investigating a breach where an attacker accessed sensitive data. The attacker used a service account token that was found in a public container image. The service account had permissions to list all Secrets in the cluster. Which of the following is the MOST likely threat actor and attack vector combination?
Select an answer first - 14
A DevOps team uses a shared Kubernetes cluster for multiple applications. A disgruntled employee who recently left the company still has a valid service account token that was never revoked. Which threat actor does this scenario primarily illustrate?
Select an answer first - 15
Which of the following is considered sensitive configuration data in a Kubernetes environment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.