Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: merry71

Free Kubernetes and Cloud Native Security Associate (KCSA) Practice Questions

Exams4sure Dumps

Exam style questions across every KCSA domain

Last Update 1 day ago
Total Questions : 60

Start with our free KCSA practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real Kubernetes and Cloud Native exam. Each KCSA exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your Linux Foundation weak domains, see where you're losing marks, and build a focused study plan in minutes.

KCSA PDF

KCSA PDF (Printable)
$46.5
$154.99

KCSA Testing Engine

KCSA PDF (Printable)
$51
$169.99

KCSA PDF + Testing Engine

KCSA PDF (Printable)
$63.9
$212.99
Question # 1

A Kubernetes cluster tenant can launch privileged Pods in contravention of therestricted Pod Security Standardmandated for cluster tenants and enforced by the built-inPodSecurity admission controller.

The tenant has full CRUD permissions on the namespace object and the namespaced resources. How did the tenant achieve this?

Options:

A.  

The scope of the tenant role means privilege escalation is impossible.

B.  

By tampering with the namespace labels.

C.  

By deleting the PodSecurity admission controller deployment running in their namespace.

D.  

By using higher-level access credentials obtained reading secrets from another namespace.

Discussion 0
Question # 2

In a cluster that contains Nodes withmultiple container runtimesinstalled, how can a Pod be configured to be created on a specific runtime?

Options:

A.  

By using a command-line flag when creating the Pod.

B.  

By modifying the Docker daemon configuration.

C.  

By setting the container runtime as an environment variable in the Pod.

D.  

By specifying the container runtime in the Pod's YAML file.

Discussion 0
Question # 3

Which of the following statements correctly describes a container breakout?

Options:

A.  

A container breakout is the process of escaping the container and gaining access to the Pod's network traffic.

B.  

A container breakout is the process of escaping a container when it reaches its resource limits.

C.  

A container breakout is the process of escaping the container and gaining access to the cloud provider's infrastructure.

D.  

A container breakout is the process of escaping the container and gaining access to the host operating system.

Discussion 0
Question # 4

When should soft multitenancy be used over hard multitenancy?

Options:

A.  

When the priority is enabling resource sharing and efficiency between tenants.

B.  

When the priority is enabling complete isolation between tenants.

C.  

When the priority is enabling fine-grained control over tenant resources.

D.  

When the priority is enabling strict security boundaries between tenants.

Discussion 0
Question # 5

Which standard approach to security is augmented by the 4C’s of Cloud Native security?

Options:

A.  

Zero Trust

B.  

Least Privilege

C.  

Defense-in-Depth

D.  

Secure-by-Design

Discussion 0
Question # 6

Which of the following statements regarding a container run with privileged: true is correct?

Options:

A.  

A container run with privileged: true within a cluster can access all Secrets used within that cluster.

B.  

A container run with privileged: true within a Namespace can access all Secrets used within that Namespace.

C.  

A container run with privileged: true on a node can access all Secrets used on that node.

D.  

A container run with privileged: true has no additional access to Secrets than if it were run with privileged: false.

Discussion 0
Question # 7

What was the name of the precursor to Pod Security Standards?

Options:

A.  

Container Runtime Security

B.  

Kubernetes Security Context

C.  

Container Security Standards

D.  

Pod Security Policy

Discussion 0
Question # 8

What is the purpose of the Supplier Assessments and Reviews control in the NIST 800-53 Rev. 5 set of controls for Supply Chain Risk Management?

Options:

A.  

To evaluate and monitor existing suppliers for adherence to security requirements.

B.  

To conduct regular audits of suppliers' financial performance.

C.  

To establish contractual agreements with suppliers.

D.  

To identify potential suppliers for the organization.

Discussion 0
Question # 9

Which step would give an attacker a foothold in a cluster butno long-term persistence?

Options:

A.  

Modify Kubernetes objects stored within etcd.

B.  

Modify file on host filesystem.

C.  

Starting a process in a running container.

D.  

Create restarting container on host using Docker.

Discussion 0
Question # 10

How can a user enforce thePod Security Standardwithout third-party tools?

Options:

A.  

Through implementing Kyverno or OPA Policies.

B.  

Use the PodSecurity admission controller.

C.  

It is only possible to enforce the Pod Security Standard with additional tools within the cloud native ecosystem.

D.  

No additional measures have to be taken to enforce the Pod Security Standard.

Discussion 0

Free Exams Sample Questions