
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 3Objective 6
Auditing and Monitoring KCSA Practice Questions (Page 2)
Part of the Kubernetes Security Fundamentals domain, which accounts for 22% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
7concepts
22%of the exam
Questions 6–10
- 6
A cluster administrator wants to ensure that communication between the kubelet and the API server is encrypted. They have already configured TLS for the API server. What additional configuration is needed?
Select an answer first - 7
A security architect is designing a multi-tenant cluster and wants to ensure that tenants cannot access the control plane's internal components. Which trust boundary control is most effective?
Select an answer first - 8
A security team wants to send audit logs to an external SIEM and also retain a local copy for compliance. Which audit backend configuration should they use?
Select an answer first - 9
Which Kubernetes feature encrypts sensitive data at rest in etcd?
Select an answer first - 10
A security analyst is investigating a suspicious API call and needs to determine the exact time the request was made. Which audit log field should they examine?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.