
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 3Objective 1
Cluster Components Security KCSA Practice Questions (Page 4)
Part of the Kubernetes Security Fundamentals domain, which accounts for 22% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
5concepts
22%of the exam
Questions 16–19
- 16
Which Kubernetes feature is used to control which users or service accounts can perform operations on etcd through the Kubernetes API?
Select an answer first - 17
What is the default behavior of Kubernetes regarding Pod-to-Pod network traffic?
Select an answer first - 18
What is a recommended practice to protect persistent data in Kubernetes against data loss?
Select an answer first - 19
A security auditor is reviewing a Kubernetes cluster and finds that the etcd database, which stores all cluster secrets, is accessible on port 2379 from any pod in the cluster. The auditor requires that only the API server should be able to communicate with etcd, and that all communication should be encrypted. The cluster is managed with kubeadm. What is the minimum set of changes the administrator should implement?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to KCSA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.