
Kubernetes and Cloud Native Security Associate (KCSA)
Domain 5Objective 2
Threat Modeling Frameworks KCSA Practice Questions (Page 6)
Part of the Compliance and Security Frameworks domain, which accounts for 10% of the KCSA exam. Linux Foundation does not publish an official question count, but from its 90-minute exam (~35–60 total, ~4–6 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
6concepts
10%of the exam
Questions 26–29
- 26
Which cloud-native component introduces a unique threat modeling consideration due to its ephemeral and event-driven nature?
Select an answer first - 27
During a threat modeling exercise, a team identifies several threats with different severity levels. They need to decide which threats to address first, considering limited resources. Which step of the threat modeling process should they perform?
Select an answer first - 28
A cloud-native team is creating a data flow diagram (DFD) for a new application that uses Kubernetes, with multiple microservices and an ingress controller. They want to ensure the DFD accurately represents the system for threat modeling. What should they include in the DFD?
Select an answer first - 29
In the context of threat modeling, what does 'quantifying' a security risk typically involve?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to KCSA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Foundation. “KCSA” is a trademark of its owner, used for identification only.