
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 4Objective 7
Admission Control KCSA Practice Questions (Page 5)
Part of the Platform Security domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
8concepts
16%of the exam
Questions 21–24
- 21
Which of the following best describes the primary purpose of admission controllers in Kubernetes?
Select an answer first - 22
Which admission controller is commonly used to enforce resource limits on a namespace by rejecting requests that exceed the configured quota?
Select an answer first - 23
A user with valid credentials attempts to create a Pod that violates a custom admission policy. The request is rejected by a ValidatingAdmissionWebhook. Which sequence of events occurred?
Select an answer first - 24
You have both a MutatingAdmissionWebhook and a ValidatingAdmissionWebhook configured. The mutating webhook adds a default securityContext to every Pod. The validating webhook checks that the securityContext has a specific setting. A Pod creation request is submitted. In which order are the webhooks invoked?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to KCSA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.