
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 6Objective 2
Malicious Code Execution and Compromised Applications in Containers KCSA Practice Questions (Page 3)
Part of the Kubernetes Threat Model domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
5concepts
16%of the exam
Questions 11–15
- 11
What is the role of network policies in mitigating the impact of a compromised container?
Select an answer first - 12
A cluster administrator is designing a defense-in-depth strategy for a cluster that runs untrusted workloads. They want to limit the impact of a container breakout. Which combination of measures would be most effective?
Select an answer first - 13
A compromised container is sending sensitive data to an external server. The security team wants to limit the damage while the incident is being investigated. Which immediate action would be most effective?
Select an answer first - 14
A security team is investigating a potential compromise of a containerized application. They notice the container is making DNS queries to a domain that is not in the application's expected behavior. Which indicator of compromise is this?
Select an answer first - 15
Which container configuration is most likely to increase the risk of container escape?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.