
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 4Objective 3
Observability KCSA Practice Questions (Page 4)
Part of the Platform Security domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
6concepts
16%of the exam
Questions 16–20
- 16
Which observability data source is most useful for detecting a sudden spike in failed API requests to the Kubernetes API server?
Select an answer first - 17
In Kubernetes, where are container logs typically written by default?
Select an answer first - 18
A cluster administrator is investigating a security incident where a node was compromised. Which metric would be MOST useful to determine if the kubelet on that node is still healthy and reporting correctly?
Select an answer first - 19
Which tool is commonly used for collecting and querying metrics in a Kubernetes cluster?
Select an answer first - 20
A security analyst is investigating a potential data breach. They have access to Prometheus metrics, Jaeger traces, and audit logs. They notice a spike in API server requests from a specific service account, but the requests appear to be legitimate API calls. Which additional step would be MOST useful to determine if the service account is compromised?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.