Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Kubernetes and Cloud Native Security Associate (KCSA)

Domain 5Objective 3

Supply Chain Compliance KCSA Practice Questions (Page 3)

Part of the Compliance and Security Frameworks domain, which accounts for 10% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
7concepts
10%of the exam

Questions 11–15

  1. 11foundation · easy

    What is the purpose of a digital signature on a software artifact?

    Select an answer first
  2. 12expert · hard

    A security team is setting up continuous monitoring for their software supply chain. They have a central artifact repository and a CI/CD pipeline. They want to automatically detect when a new version of a dependency is published and assess its risk. What is the most effective approach?

    Select an answer first
  3. 13application · medium

    A company distributes a CLI tool as a container image. They want to allow customers to verify that the image was built by the company and has not been tampered with. Which mechanism should they implement?

    Select an answer first
  4. 14foundation · easy

    What is the role of the NIST SSDF in supply chain security?

    Select an answer first
  5. 15foundation · easy

    What is a provenance attestation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.