
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 4Objective 3
Observability KCSA Practice Questions (Page 5)
Part of the Platform Security domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
6concepts
16%of the exam
Questions 21–25
- 21
A security team is evaluating observability tools for their Kubernetes cluster. They need to detect anomalies in real-time, but they also need to retain historical data for compliance. They are considering Prometheus and Grafana. Which limitation of Prometheus should they address?
Select an answer first - 22
A security engineer is investigating a suspected data exfiltration from a Kubernetes cluster. They have access to Prometheus metrics showing a sudden spike in network egress from a specific pod, but the metrics do not show which destination IPs were contacted. Which additional observability data source would be MOST useful to confirm the exfiltration?
Select an answer first - 23
Which of the following is one of the three pillars of observability?
Select an answer first - 24
Which metric is most directly indicative of the health of the Kubernetes API server?
Select an answer first - 25
Which Kubernetes component is the authoritative store for cluster state and configuration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.