
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 2Objective 2
Controller Manager KCSA Practice Questions (Page 4)
Part of the Kubernetes Cluster Component Security domain, which accounts for 22% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
6concepts
22%of the exam
Questions 16–20
- 16
A security analyst wants to create an alert that triggers when the kube-controller-manager is unable to authenticate to the API server. Which of the following metrics or logs would be most useful for this alert?
Select an answer first - 17
A security team is reviewing the RBAC configuration for the kube-controller-manager. They want to ensure that the controller manager can only perform the actions it needs to manage cluster state, such as reading and updating Pods, Services, and Deployments. Which approach best aligns with the principle of least privilege?
Select an answer first - 18
What is the primary role of the kube-controller-manager in a Kubernetes cluster?
Select an answer first - 19
A developer is troubleshooting an issue where a Node has been unreachable for 10 minutes, but its Pods are still running. The developer wants to understand which controller is responsible for taking action when a Node becomes unreachable. Which controller should they investigate?
Select an answer first - 20
Which of the following is a recommended hardening practice for the kube-controller-manager?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.