
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 4Objective 2
Image Repository KCSA Practice Questions (Page 4)
Part of the Platform Security domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
6concepts
16%of the exam
Questions 16–20
- 16
What is the purpose of maintaining immutable image provenance?
Select an answer first - 17
When should container images be scanned for vulnerabilities to minimize risk?
Select an answer first - 18
Your organization uses a private registry with multiple teams. Team A needs to pull images from the 'shared' repository, but only Team B should be able to push to it. Additionally, you want to ensure that images are not tampered with after being pushed. What is the most comprehensive approach?
Select an answer first - 19
Your team uses a base image from a public repository. A vulnerability scan of your application image reports a critical vulnerability in a system library inherited from the base image. What is the most appropriate action?
Select an answer first - 20
Which practice is recommended to minimize the exposure of container images to unauthorized parties?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.