
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 4Objective 4
Service Mesh KCSA Practice Questions (Page 5)
Part of the Platform Security domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
5concepts
16%of the exam
Questions 21–25
- 21
Which deployment strategy does a service mesh commonly support by gradually shifting a percentage of traffic from an old version to a new version of a service?
Select an answer first - 22
A company wants to implement a canary release for a new version of a service. They want to monitor the error rate and latency of the new version before increasing traffic. What should they use?
Select an answer first - 23
A company is considering a service mesh but is worried about the performance overhead of sidecar proxies. They have a high-throughput application with strict latency requirements. What is the best way to evaluate the impact?
Select an answer first - 24
How does a service mesh enforce authorization policies between services?
Select an answer first - 25
A company is adopting a service mesh and wants to ensure that legacy services that do not support mTLS can still communicate with new services that do. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.