Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Kubernetes and Cloud Native Security Associate (KCSA)

Domain 6Objective 2

Malicious Code Execution and Compromised Applications in Containers KCSA Practice Questions (Page 4)

Part of the Kubernetes Threat Model domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–2 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)

22questions here
5free pages
5concepts
16%of the exam

Questions 16–20

  1. 16expert · hard

    A company is planning to use a container image from a third-party vendor. The image is not signed, and the vendor has a poor security track record. The application will process sensitive data. Which approach best mitigates the risk?

    Select an answer first
  2. 17expert · medium · select all that apply

    A security analyst is investigating a potential compromise of a containerized application. Which of the following are indicators of compromise? (Select all that apply.)

    Select an answer first
  3. 18application · medium

    A company uses a public container image that has been pulled millions of times. They want to ensure it hasn't been compromised. Which approach provides the strongest assurance?

    Select an answer first
  4. 19foundation · easy

    Which of the following is a common technique used by attackers to escape a container and gain access to the host system?

    Select an answer first
  5. 20application · medium

    A security team wants to harden a container that only needs to listen on a TCP port and write logs to stdout. They want to reduce the risk of container escape. Which configuration should they apply?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.