
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 1Objective 5
Artifact Repository and Image Security KCSA Practice Questions (Page 7)
Part of the Overview of Cloud Native Security domain, which accounts for 14% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
7concepts
14%of the exam
Questions 31–34
- 31
A security team wants to ensure that all container images in production have a complete and verifiable chain of custody from source code to deployment. They also want to automatically block any image that fails verification. Which approach should they implement?
Select an answer first - 32
What is the primary purpose of image signing?
Select an answer first - 33
A company uses a shared artifact repository for multiple teams. They need to ensure that only the platform team can modify images in the 'production' repository, while other teams can only read from it. What should they implement?
Select an answer first - 34
A security analyst discovers that a container image used in production contains a package with a known critical vulnerability. What is the most immediate risk to the organization?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to KCSA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.