
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 2Objective 5
Container Runtime KCSA Practice Questions (Page 1)
Part of the Kubernetes Cluster Component Security domain, which accounts for 22% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
8concepts
22%of the exam
Questions 1–5
- 1
Which of the following is a common method for auditing container runtime activity?
Select an answer first - 2
A security team is hardening a Kubernetes cluster that runs untrusted workloads. They want to minimize the attack surface while maintaining compatibility with standard container images. Which combination of runtime hardening measures is most effective?
Select an answer first - 3
A security analyst needs to audit container runtime activity to detect attempts to exploit known vulnerabilities. Which approach provides the most comprehensive audit trail?
Select an answer first - 4
A security team is evaluating a new container runtime for their Kubernetes cluster. They want to ensure that the runtime can be managed by kubelet through the standard interface and that it supports the Kubernetes Container Runtime Interface (CRI). Which runtime should they select?
Select an answer first - 5
Which task is part of image management performed by a container runtime?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.