Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Kubernetes and Cloud Native Security Associate (KCSA)

Domain 2Objective 5

Container Runtime KCSA Practice Questions (Page 5)

Part of the Kubernetes Cluster Component Security domain, which accounts for 22% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
8concepts
22%of the exam

Questions 21–25

  1. 21application · medium

    A cluster administrator wants to run containers without root privileges inside the container to reduce the risk of privilege escalation. Which runtime security feature should they enable?

    Select an answer first
  2. 22application · medium

    A security team wants to ensure that a container cannot make certain system calls that could be dangerous. Which runtime isolation mechanism should they configure?

    Select an answer first
  3. 23application · medium

    A security administrator wants to prevent a container from seeing the host's process list. Which isolation mechanism provided by the container runtime should be configured?

    Select an answer first
  4. 24foundation · easy

    Which of the following is a recommended best practice for hardening a container runtime in Kubernetes?

    Select an answer first
  5. 25foundation · easy

    What is the purpose of dropping capabilities in a container runtime?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.