
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 3Objective 4
Data Protection KCSA Practice Questions (Page 1)
Part of the Kubernetes Security Fundamentals domain, which accounts for 22% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 14 practice questions to prepare you well beyond it. (estimate)
14questions here
3free pages
5concepts
22%of the exam
Questions 1–5
- 1
A developer accidentally committed a Kubernetes Secret manifest to a public Git repository. The Secret contains a production API key. The team needs to remediate the exposure. Which action should be taken FIRST?
Select an answer first - 2
A security team wants to ensure that Secrets are not exposed in logs. They have enabled encryption at rest and restricted RBAC. Which additional measure should they implement to prevent Secrets from appearing in audit logs?
Select an answer first - 3
A security policy requires that Secrets be encrypted at rest in etcd. The cluster is already running with the default configuration. What must be done to enable encryption at rest?
Select an answer first - 4
Which of the following is a recommended way to restrict access to Secrets in a Kubernetes cluster?
Select an answer first - 5
What is the primary difference between a Kubernetes Secret and a ConfigMap?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.