
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 4Objective 1
Supply Chain Security KCSA Practice Questions (Page 2)
Part of the Platform Security domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
13concepts
16%of the exam
Questions 6–10
- 6
A platform team wants to ensure that only container images with no known critical or high vulnerabilities are deployed to their production cluster. They already use a container registry that supports image scanning. Which approach should they use to enforce this requirement at deployment time?
Select an answer first - 7
A company uses a monorepo containing multiple services. They want to enforce that only the CI/CD system can merge changes to the main branch, and that all other merges must go through a pull request with at least two approvals. However, they also want to allow emergency hotfixes to be deployed quickly. Which approach balances security and operational flexibility?
Select an answer first - 8
After a security incident, a company needs to quickly determine which of their deployed container images contain a specific vulnerable library. They have images running in production but did not keep track of the components in each image. What should they do to enable this analysis in the future?
Select an answer first - 9
What is the purpose of a software attestation?
Select an answer first - 10
Which practice is essential to ensure the integrity of a CI/CD pipeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.