
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 4Objective 7
Admission Control KCSA Practice Questions (Page 1)
Part of the Platform Security domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
8concepts
16%of the exam
Questions 1–5
- 1
Which kube-apiserver flag is used to enable a specific set of admission controllers?
Select an answer first - 2
What is the security implication of setting `failurePolicy: Ignore` on a validating admission webhook?
Select an answer first - 3
A security team has deployed a ValidatingWebhookConfiguration that enforces a critical security policy. The webhook server is running, but the team wants to ensure that if the webhook server crashes, the API server does not allow requests that violate the policy. Which failurePolicy should be configured and what is the trade-off?
Select an answer first - 4
Which field in a webhook configuration is used to restrict the webhook to only be invoked for resources in specific namespaces?
Select an answer first - 5
In the Kubernetes API request lifecycle, at what point do admission controllers execute relative to authentication and authorization?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.