
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 6Objective 3
Attacker on the Network KCSA Practice Questions (Page 4)
Part of the Kubernetes Threat Model domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
7concepts
16%of the exam
Questions 16–20
- 16
An attacker on the cluster network sends traffic that appears to come from a legitimate service's IP address. Which network attack technique does this describe?
Select an answer first - 17
Which scenario is most vulnerable to unencrypted traffic?
Select an answer first - 18
A developer exposes a database service using a NodePort service to allow external access for debugging. The security team is concerned about the risk. Which action should be taken to reduce the risk while still allowing debugging?
Select an answer first - 19
A security analyst is investigating a potential network attack. The analyst notices that a pod is making connections to an IP address that is not in the cluster's known service list. The analyst suspects that the pod is communicating with a command-and-control server. Which monitoring technique would be most effective in confirming this?
Select an answer first - 20
A company runs a microservices application in a Kubernetes cluster. The application uses a service mesh to encrypt traffic between services. However, the security team discovers that traffic between the service mesh sidecar and the application container is unencrypted. An attacker with access to the pod could intercept this traffic. Which action should be taken to mitigate this risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.