Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Kubernetes and Cloud Native Security Associate (KCSA)

Domain 3Objective 4

Data Protection KCSA Practice Questions (Page 3)

Part of the Kubernetes Security Fundamentals domain, which accounts for 22% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 14 practice questions to prepare you well beyond it. (estimate)

14questions here
3free pages
5concepts
22%of the exam

Questions 11–14

  1. 11foundation · easy

    Which practice is a recommended security best practice for protecting Kubernetes Secrets?

    Select an answer first
  2. 12foundation · easy

    Which Kubernetes Secret type is used to store a TLS certificate and private key for securing ingress traffic?

    Select an answer first
  3. 13application · medium

    An application needs to authenticate to an external service using a client certificate and a private key. The team wants to store these in a Kubernetes Secret and mount them into the Pod. Which Secret type should they use?

    Select an answer first
  4. 14expert · hard

    A company runs a multi-tenant Kubernetes cluster. One team needs to mount a Secret as a volume in their Pods, but the security team is concerned about the Secret being visible to other tenants via the API. The cluster has encryption at rest enabled and RBAC is configured. Which additional measure should be taken to protect the Secret from other tenants?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to KCSA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.