
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 1Objective 5
Artifact Repository and Image Security KCSA Practice Questions (Page 5)
Part of the Overview of Cloud Native Security domain, which accounts for 14% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
7concepts
14%of the exam
Questions 21–25
- 21
A developer is creating a Dockerfile for a Node.js application. They want to ensure the image is as secure as possible. Which of the following practices is most important?
Select an answer first - 22
A DevOps team uses a private artifact repository to store container images. They want to automatically block any image that contains a known critical vulnerability from being deployed. Which approach should they implement?
Select an answer first - 23
How do image scanning tools typically detect vulnerabilities in container images?
Select an answer first - 24
A company uses a private registry and wants to ensure that only images signed by their CI system can be deployed. They also want to allow developers to pull images for local testing without restrictions. What is the best way to achieve this?
Select an answer first - 25
A company wants to reduce the number of vulnerabilities in their container images. They have a large number of existing images and a limited budget. Which strategy is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.