
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 2Objective 1
API Server KCSA Practice Questions (Page 2)
Part of the Kubernetes Cluster Component Security domain, which accounts for 22% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
9concepts
22%of the exam
Questions 6–10
- 6
A security team wants to ensure that no pod in the cluster can run with privileged containers, and they want this enforced even if a user has RBAC permissions to create pods. Which mechanism should they configure?
Select an answer first - 7
Which authorization mode in Kubernetes allows the API server to delegate authorization decisions to an external service?
Select an answer first - 8
An organization wants to integrate their existing identity provider (IdP) with Kubernetes so that users authenticate with their corporate credentials and group memberships are automatically reflected in RBAC. Which authentication mechanism should they configure on the API server?
Select an answer first - 9
How does a pod typically authenticate to the Kubernetes API server?
Select an answer first - 10
Which audit log level in Kubernetes records the request and response bodies?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.