
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 2Objective 6
KubeProxy KCSA Practice Questions (Page 2)
Part of the Kubernetes Cluster Component Security domain, which accounts for 22% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 17 practice questions to prepare you well beyond it. (estimate)
17questions here
4free pages
4concepts
22%of the exam
Questions 6–10
- 6
A DevOps team is troubleshooting why a Service of type ClusterIP is not reachable from pods on other nodes. They verify that the Service endpoints are correct and that the kubelet is healthy. Which component's role is most directly responsible for making the ClusterIP reachable across nodes?
Select an answer first - 7
Which kube-proxy mode uses the kernel's IPVS module to provide load balancing and supports more scheduling algorithms than iptables?
Select an answer first - 8
Which kube-proxy mode uses a userspace proxy process to handle service traffic and was the default in early Kubernetes versions?
Select an answer first - 9
A developer is debugging why a Service is not reachable from a pod on the same node. They check the Service and Endpoints and they are correct. What should they check next to determine if kube-proxy is functioning correctly?
Select an answer first - 10
A developer is confused about why a Service of type NodePort is accessible from outside the cluster. They ask the administrator to explain the role of kube-proxy in this scenario. Which explanation is accurate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.