
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 1Objective 2
Cloud Provider and Infrastructure Security KCSA Practice Questions (Page 1)
Part of the Overview of Cloud Native Security domain, which accounts for 14% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
4concepts
14%of the exam
Questions 1–5
- 1
In the shared responsibility model for cloud computing, which statement correctly describes the division of security responsibilities for an IaaS (Infrastructure as a Service) offering?
Select an answer first - 2
A company must comply with a regulation that requires audit logs of all access to sensitive data stored in a cloud object storage service. Which action should the company take to meet this requirement?
Select an answer first - 3
A company runs a multi-tenant Kubernetes cluster on a cloud provider. They need to ensure that tenants cannot access each other's resources, while also meeting compliance requirements for logging. Which set of controls should they implement?
Select an answer first - 4
A company runs a production Kubernetes cluster on a cloud provider. They want to minimize the risk of a compromised node affecting other nodes. Which best practice should they implement?
Select an answer first - 5
A company runs a production cluster on a cloud provider. They want to detect and respond to suspicious activities, such as unusual API calls or network connections. Which best practice should they implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.