
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 4Objective 5
PKI KCSA Practice Questions (Page 5)
Part of the Platform Security domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
7concepts
16%of the exam
Questions 21–25
- 21
A security team is reviewing how private keys are stored on Kubernetes worker nodes. They want to ensure that the kubelet client certificate private key is protected. What is the best practice?
Select an answer first - 22
A developer wants to create a custom controller that requests a certificate for a new webhook. They plan to use Kubernetes' built-in CSR API. What is the correct sequence of steps?
Select an answer first - 23
What is the purpose of certificate revocation?
Select an answer first - 24
A new administrator is troubleshooting why a kubelet cannot authenticate to the kube-apiserver. The kubelet certificate is signed by a different CA than the one the API server trusts. What is the root cause?
Select an answer first - 25
A cluster administrator notices that the kube-apiserver certificate is about to expire. The cluster was provisioned with kubeadm. What is the recommended way to renew this certificate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.