
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 6Objective 1
Denial of Service KCSA Practice Questions (Page 5)
Part of the Kubernetes Threat Model domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
16%of the exam
Questions 21–25
- 21
A security operations team is setting up monitoring for a Kubernetes cluster to detect DoS attacks. They want to detect both network-level floods and application-level resource exhaustion. They also want to be able to respond quickly to mitigate the attack. Which combination of monitoring and response capabilities should they implement?
Select an answer first - 22
A Kubernetes cluster hosts a microservices application. The frontend service is exposed to the internet, and the backend service should only be reachable from the frontend. An attacker is flooding the backend service directly with traffic, causing it to become overloaded. Which action would most directly mitigate this network-based DoS vector?
Select an answer first - 23
Which Kubernetes metric is most directly useful for detecting a CPU-based resource exhaustion attack on a workload?
Select an answer first - 24
What is the primary purpose of a LimitRange in a Kubernetes namespace?
Select an answer first - 25
A Kubernetes cluster hosts multiple teams in shared namespaces. One team's application is known to have memory leaks, and the administrator wants to ensure that a single pod cannot consume all the memory of a node, affecting other workloads. Which Kubernetes resource should be configured to enforce a maximum memory limit per pod?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.