
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 3Objective 6
Auditing and Monitoring KCSA Practice Questions (Page 5)
Part of the Kubernetes Security Fundamentals domain, which accounts for 22% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
7concepts
22%of the exam
Questions 21–25
- 21
A security analyst is reviewing audit logs and notices a series of events where a service account named 'ci-builder' is creating pods with hostPath volumes that mount the host's /etc directory. The service account has cluster-admin privileges. Which finding is the most critical security concern?
Select an answer first - 22
In an audit policy file, what is the effect of a rule that specifies 'level: None'?
Select an answer first - 23
In a Kubernetes audit log event, which field identifies the stage of the request handling at which the event was generated?
Select an answer first - 24
A company wants to ensure that data transmitted between the kubelet and the API server is encrypted. They have already enabled TLS for the API server. What else must be configured?
Select an answer first - 25
In the data flow of a Kubernetes cluster, which component is responsible for persisting the cluster state?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.