
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 4Objective 3
Observability KCSA Practice Questions (Page 2)
Part of the Platform Security domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
6concepts
16%of the exam
Questions 6–10
- 6
A security analyst is trying to determine if a pod was compromised by comparing its behavior to a baseline. They have access to logs, metrics, and traces. Which approach would be MOST effective?
Select an answer first - 7
What is the purpose of Kubernetes audit logging?
Select an answer first - 8
Which file is used to configure Kubernetes audit logging policies?
Select an answer first - 9
A platform team is designing a centralized logging solution for a multi-tenant cluster. They need to collect logs from all namespaces, but they want to avoid giving tenants access to logs from other tenants. Which approach would BEST satisfy this requirement?
Select an answer first - 10
A security analyst is correlating data from multiple sources to detect a potential brute-force attack on the Kubernetes API server. Which combination of observability data would be MOST effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.