
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 5Objective 1
Compliance Frameworks KCSA Practice Questions (Page 1)
Part of the Compliance and Security Frameworks domain, which accounts for 10% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
5concepts
10%of the exam
Questions 1–5
- 1
A company handles both health records and credit card data in the same Kubernetes cluster. They need to comply with both HIPAA and PCI DSS. What is a key challenge they will face?
Select an answer first - 2
An auditor requires evidence that all changes to a Kubernetes cluster are reviewed and approved. The team has audit logging enabled but no formal change management process. What should they do to satisfy this requirement?
Select an answer first - 3
A financial services company is preparing for a SOC 2 audit of their Kubernetes environment. The auditor requires evidence of who accessed the cluster and what actions they performed. Which approach should the team take to meet this requirement?
Select an answer first - 4
A company must comply with SOC 2's requirement for logical and physical access controls. They have a Kubernetes cluster with sensitive workloads. Which combination of controls should they implement to address both logical and physical access?
Select an answer first - 5
To meet encryption requirements from frameworks like PCI DSS, what should be configured in a Kubernetes cluster?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.