Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Foundation logo

Kubernetes and Cloud Native Security Associate (KCSA)

Domain 5Objective 2

Threat Modeling Frameworks KCSA Practice Questions (Page 4)

Part of the Compliance and Security Frameworks domain, which accounts for 10% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
6concepts
10%of the exam

Questions 16–20

  1. 16application · medium

    A security team is evaluating threat modeling methodologies for a legacy monolithic application that is being migrated to Kubernetes. They need a methodology that focuses on business impact and risk, and that involves stakeholders from business, development, and security. Which methodology aligns best with this requirement?

    Select an answer first
  2. 17expert · hard

    A company is migrating a monolithic application to a microservices architecture on Kubernetes. The security team wants to perform threat modeling to identify risks introduced by the new architecture. They have limited time and need to focus on the most critical areas. Which approach is most effective?

    Select an answer first
  3. 18application · medium

    A security architect is leading a threat modeling session for a new microservices-based payment platform. The team needs to identify threats across all components, including the API gateway, individual services, and the message queue. They want a structured approach that systematically examines each component from multiple perspectives, such as spoofing, tampering, and repudiation. Which methodology should they use?

    Select an answer first
  4. 19expert · hard

    A security architect is threat modeling a multi-tenant SaaS platform built on Kubernetes. Each tenant's data is isolated using namespaces and network policies. The team has identified a threat of cross-tenant data access via a compromised pod. They need to prioritize this threat against other identified threats. Which factor should be most heavily weighted in the prioritization?

    Select an answer first
  5. 20application · medium

    A security engineer is using an automated threat modeling tool that integrates with their CI/CD pipeline. The tool generates a data flow diagram from the application's code and infrastructure definitions. What is the primary benefit of using such a tool in this context?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.