Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: merry71

Free Cilium Certified AssociateCCA Practice Questions

Exams4sure Dumps

Exam style questions across every Cilium-Associate domain

Last Update 4 days ago
Total Questions : 60

Start with our free Cilium-Associate practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real Cloud & Containers exam. Each Cilium-Associate exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your Linux Foundation weak domains, see where you're losing marks, and build a focused study plan in minutes.

Cilium-Associate PDF

Cilium-Associate PDF (Printable)
$46.5
$154.99

Cilium-Associate Testing Engine

Cilium-Associate PDF (Printable)
$51
$169.99

Cilium-Associate PDF + Testing Engine

Cilium-Associate PDF (Printable)
$63.9
$212.99
Question # 11

A Kubernetes cluster is not currently running Cilium as a CNI, but the user would like to benefit from Hubbies observability capabilities on your cluster. Which one of the following options is NOT possible?

Options:

A.  

Migrating to Cilium and Hubble by reconfiguring /etc/cni/net .6/ to point to Cilium and restarting the nodes, accepting an outage.

B.  

Install Hubble on the cluster without Cilium. Hubble can be deployed in a standalone model by downloading and installing the Hubble binary

C.  

Install Cilium and Hubble on top of the cluster in a CNI chaining model, without disrupting the existing CNI.

D.  

Migrating to Cilium and Hubble on a node-by-node basis, without requiring a complete cluster outage, by using Dual Overlays.

Discussion 0
Question # 12

Which Cilium command should you execute to gather network-related troubleshooting information from your Kubernetes cluster?

Options:

A.  

cilium bugtool

B.  

cilium debuginfo

C.  

cilium status --verbose

D.  

cilium sysduwp

Discussion 0
Question # 13

Which of these observability features is NOT supported by Hubble?

Options:

A.  

Hubble Is able to filter flows based on a given Kubernetes node name.

B.  

Hubble Is able to provide Layer 7 visibility In eBPF, without the need for a proxy.

C.  

Hubble is able to observe by HTTP Status code (like "404" or "200").

D.  

Hubble is able to filter traffic based on the network policy verdict.

Discussion 0
Question # 14

Which encapsulation protocols are supported when configuring Cilium in tunnel mode?

Options:

A.  

MPLS and Geneve

B.  

VXLAN and Geneve

C.  

OTV and STT

D.  

EVPN and VXLAN

Discussion 0
Question # 15

Which question does Hubble provide the information to answer?

Options:

A.  

What is the configuration of Cilium B6P?

B.  

Which container database query ran the longest?

C.  

Which containers have the highest CPU utilization?

D.  

Which services had connections blocked due to network policy?

Discussion 0
Question # 16

We observed Hubble output:

Question # 16

Question 7 Hubble flow exhibit

Explain what may have happened:

Options:

A.  

On test pod (default namespace), someone launched commands:

curl 19.244.0.191 #Output: Failed

curl 16.244.0.191:8680 #Output: Succeeded

B.  

On test2 pod (default namespace), someone launched commands:

curl 16.244.0.143 #Output: Failed curl 10.244.0.143:8080 #Output: Succeeded

C.  

On test2 pod (default namespace), someone launched commands:

curl 10.244.0.143 #Output: Succeeded curl 10.244.0.143:8080 #Output: Failed

D.  

On test pod (default namespace), someone launched commands: curl 16.244.0.191 #Output: Succeeded curl ie.244.0.191:8080 #Output: Failed

Discussion 0
Question # 17

What is correct about this Cilium Network Policy?

Question # 17

Question 21 Cilium Network Policy exhibit

Options:

A.  

It will allow all traffic to the Kubemetes DNS servers from any pod in the default namespace.

B.  

It will allow all traffic to the Kubernetes DNS servers from any pod across all namespaces in the cluster

C.  

It will deny all traffic to the Kubernetes DNS servers from any pod across all namespaces in the cluster.

D.  

It will deny all traffic to the Kubernetes DNS servers from any pod in the default namespace.

Discussion 0
Question # 18

Which one of the following statements accurately describes the identity-based network security model used by Cilium?

Options:

A.  

Security is based on the identity of a pod, which Is derived through its IP address. This identity cannot be shared between pods.

B.  

Security is based on the identity of a pod, which is derived through annotations. This Identity can be shared between pods.

C.  

Security is based on the identity of a pod, which is derived through labels. This identity can be shared between pods.

D.  

Security is based on the identity of a pod. The security ID is manually set by the operator and cannot be shared between pods.

Discussion 0

Free Exams Sample Questions