
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 4Objective 2
Image Repository KCSA Practice Questions (Page 2)
Part of the Platform Security domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
6concepts
16%of the exam
Questions 6–10
- 6
Your organization uses a private container registry for all production images. Developers need to push images, but only the CI/CD pipeline should be able to deploy to production. You must ensure that developers cannot modify or overwrite production tags. What should you implement?
Select an answer first - 7
Your cluster uses a policy engine to require that all images are signed by a trusted key. A developer reports that a new image cannot be deployed, and the error indicates a signature verification failure. What is the most likely cause?
Select an answer first - 8
What is the primary purpose of image signing?
Select an answer first - 9
Your organization has a shared registry with multiple namespaces. The security team wants to ensure that developers can only push images to their own team's namespace and cannot pull images from other teams' namespaces. What should you implement?
Select an answer first - 10
Your security team wants to ensure that only images signed by your organization's private key can be deployed in the cluster. You have configured the container runtime to verify signatures. What additional step is required to make this effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.