Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Kubernetes and Cloud Native Security Associate (KCSA)

Domain 6Objective 2

Malicious Code Execution and Compromised Applications in Containers KCSA Practice Questions (Page 1)

Part of the Kubernetes Threat Model domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)

22questions here
5free pages
5concepts
16%of the exam

Questions 1–5

  1. 1foundation · easy

    What is the purpose of using seccomp in a container runtime?

    Select an answer first
  2. 2expert · hard

    A cluster administrator is designing a defense-in-depth strategy for a multi-tenant cluster. They want to limit the impact of a container breakout in one tenant. Which combination of measures would be most effective?

    Select an answer first
  3. 3expert · hard

    A security engineer is investigating a container escape. The container was running with a non-root user and had no capabilities added. However, the attacker was able to gain root access on the host. Which of the following is the most likely vector?

    Select an answer first
  4. 4application · medium

    A security analyst notices that a containerized application is spawning new processes that are not part of its normal operation, and the container's root filesystem has been modified. Which runtime security measure would directly detect and block these behaviors?

    Select an answer first
  5. 5foundation · easy

    Which runtime security measure makes the container's root filesystem read-only?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.