
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 6Objective 3
Attacker on the Network KCSA Practice Questions (Page 3)
Part of the Kubernetes Threat Model domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
7concepts
16%of the exam
Questions 11–15
- 11
A company exposes a web application via an Ingress resource. The application is also accessible via a NodePort service for debugging. The security team wants to minimize the attack surface while keeping the application accessible. Which action should be taken?
Select an answer first - 12
Which of the following is a technique for detecting suspicious network behavior in a Kubernetes cluster?
Select an answer first - 13
What is the primary purpose of Kubernetes Network Policies?
Select an answer first - 14
A company runs a web application in a Kubernetes cluster. The application is exposed to the internet via a LoadBalancer service. A security audit reveals that traffic between the external client and the LoadBalancer is encrypted, but traffic between the LoadBalancer and the backend pods is not. An attacker with access to the cluster network could potentially intercept this internal traffic. Which action would most directly address this vulnerability?
Select an answer first - 15
How do Network Policies help limit an attacker's lateral movement within a cluster?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.