
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 5Objective 3
Supply Chain Compliance KCSA Practice Questions (Page 4)
Part of the Compliance and Security Frameworks domain, which accounts for 10% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
7concepts
10%of the exam
Questions 16–20
- 16
A security incident occurs: a popular open-source library was compromised, and a malicious version was published to a public registry. The company's applications use this library. The security team needs to respond. They have a central artifact repository that caches dependencies. What is the most effective immediate response?
Select an answer first - 17
Which of the following is a common supply chain threat?
Select an answer first - 18
A software vendor distributes a binary application. They want to provide a way for customers to verify that the binary was produced by them and has not been altered. They are considering publishing a SHA-256 checksum and a detached GPG signature. Which statement correctly describes the security properties of these two mechanisms?
Select an answer first - 19
Which of the following best describes the software supply chain?
Select an answer first - 20
A company is migrating from a monolithic application to a microservices architecture. They currently manage dependencies by manually updating a shared library. They want to adopt a more secure and scalable approach. Which practice is most aligned with supply chain security best practices?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.