
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 4Objective 1
Supply Chain Security KCSA Practice Questions (Page 3)
Part of the Platform Security domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
13concepts
16%of the exam
Questions 11–15
- 11
A company's container registry was compromised, and an attacker replaced a legitimate image with a malicious one that has the same tag. The company's deployment pipeline pulls images by tag, not digest. What is the most effective way to prevent this type of attack in the future?
Select an answer first - 12
Why is it recommended to use minimal base images for containers?
Select an answer first - 13
Which phase of a Secure Software Development Lifecycle (SSDLC) involves conducting code reviews and static analysis to identify vulnerabilities early?
Select an answer first - 14
What is the primary purpose of container image scanning?
Select an answer first - 15
What is the primary purpose of a lock file (e.g., package-lock.json or requirements.txt with pinned versions)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.