
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 1Objective 2
Cloud Provider and Infrastructure Security KCSA Practice Questions (Page 4)
Part of the Overview of Cloud Native Security domain, which accounts for 14% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~5–8 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
4concepts
14%of the exam
Questions 16–20
- 16
Which practice is a fundamental best practice for securing cloud infrastructure?
Select an answer first - 17
A company is migrating from an on-premises data center to a cloud IaaS environment. They have a compliance requirement to maintain full control over their data and ensure that no third party can access it. Which deployment model best meets this requirement?
Select an answer first - 18
A company uses a cloud provider's managed Kubernetes service. They want to ensure that only specific IP addresses can access the Kubernetes API server, and that all API calls are recorded for security analysis. Which combination of controls should they use?
Select an answer first - 19
What is the customer's role in maintaining governance in a cloud environment?
Select an answer first - 20
A company uses a cloud provider's managed Kubernetes service. They need to restrict which users can create or modify pods in the cluster. Which cloud provider control should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.