
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 6Objective 1
Denial of Service KCSA Practice Questions (Page 6)
Part of the Kubernetes Threat Model domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
16%of the exam
Questions 26–28
- 26
A security engineer is concerned about an attacker flooding the Kubernetes API server with authentication requests, which could overwhelm the control plane and affect all cluster operations. Which built-in Kubernetes feature should they configure to protect the API server from such overload?
Select an answer first - 27
What is the primary purpose of the Cluster Autoscaler in the context of DoS resilience?
Select an answer first - 28
A company runs a stateless web service on Kubernetes. During a DDoS attack, the service experiences a sudden spike in traffic, and the current number of replicas is insufficient to handle the load, causing availability issues. The team wants to maintain availability during such events without manual intervention. Which configuration should they implement?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to KCSA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.