
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 4Objective 1
Supply Chain Security KCSA Practice Questions (Page 8)
Part of the Platform Security domain, which accounts for 16% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~6–10 in this domain), expect 1–1 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
13concepts
16%of the exam
Questions 36–40
- 36
A company wants to ensure that only images signed by their CI/CD pipeline can be deployed to their Kubernetes cluster. They have implemented image signing using cosign. What additional component is required to enforce this policy at deployment time?
Select an answer first - 37
A company distributes a CLI tool as a container image. To help customers verify that the image they pull is exactly what the company published and has not been tampered with, the company wants to provide a way for customers to check the image's authenticity and integrity. Which artifact should the company publish alongside the image?
Select an answer first - 38
A company is adopting a secure software development lifecycle (SSDLC) for their cloud native applications. They want to integrate security activities into each phase of development, from design to deployment. Which practice best exemplifies integrating security into the development phase?
Select an answer first - 39
What is the purpose of pinning dependency versions in a project?
Select an answer first - 40
In a Secure Software Development Lifecycle (SSDLC), what is the primary purpose of the 'design' phase?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.