
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 4Objective 6
Connectivity KCSA Practice Questions (Page 1)
Part of the Platform Security domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
7concepts
16%of the exam
Questions 1–5
- 1
A security team wants to prevent DNS-based attacks in a Kubernetes cluster. They have a requirement to allow pods to resolve only specific internal and external domains. They also want to detect DNS tunneling. Which approach should they implement?
Select an answer first - 2
What is a key security feature provided by a service mesh like Istio?
Select an answer first - 3
A security team wants to prevent pods from resolving internal service names that are not part of their application. They also want to prevent DNS tunneling. Which configuration should they implement?
Select an answer first - 4
A company runs a Kubernetes cluster with multiple namespaces. They need to ensure that all traffic between pods in different namespaces is encrypted. They are considering using a service mesh. What is the primary benefit of using a service mesh for this requirement?
Select an answer first - 5
Which Kubernetes resource is commonly used to implement network segmentation between workloads?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.