Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: chrismas

Free Practice Questions for the Linux Foundation Cloud & Containers Cilium-Associate Exam (2026 Updated)

At Marks4sure, we are dedicated to providing IT professionals with the most accurate and reliable preparation materials for the Linux Foundation Cilium-Associate exam. To support your certification journey, we have made a selection of our premium 2026 Cloud & Containers practice questions and answers available completely free. You can take this practice test as many times as you need. Every question includes a detailed, expertly verified explanation to ensure you fully grasp the core security concepts before test day.

Questions 4

What is a correct statement related to BIG TCP, an eBPF-based feature in Cilium?

Options:

A.

BIG TCP requires updating the Maximum Transmission Unit (MTU) across the network.

B.

While BIG TCP increases the transactions count, it causes higher latency between pods.

C.

BIG TCP addresses the limitation in the size of the packets, caused by the 16-bit length field in the IP header.

D.

BIG TCP is incompatible with features like GRO (Generic Receive Offload) and TSO (Transmit Segmentation Offload).

Buy Now
Questions 5

Which Cilium configuration is recommended to help identify the correct configuration of network policies without interrupting workload communications?

Options:

A.

DNS enforcement mode

B.

HTTP audit mode

C.

Policy enforcement mode

D.

Policy audit mode

Buy Now
Questions 6

What is true about WireGuard encryption on Cilium?

Options:

A.

Packets are encrypted when they are destined to the same node from which they were sent. This is to ensure confidentiality of traffic within the node.

B.

It provides encryption for node-to-node, pod-to-node, node-to-pod, and pop-to-pod traffic as long as the pods are on different nodes.

C.

When running in the tunneling mode, pod-to-pod traffic will be sent over the WireGuard tunnel before being transmitted over the overlay tunnel.

D.

When WireGuard is enabled in Cilium, each pod will establish a secure WireGuard tunnel between it and all other known pods in the cluster.

Buy Now
Questions 7

Which statement is true of both the Ingress Controller and Gateway API?

Options:

A.

It provides portable Layer 7 north-south routing logic for Kubernetes workloads.

B.

Its routing logic can be restricted to a single namespace.

C.

It is role-oriented, with some resources for administrators and others for users.

D.

Its features are commonly extended by using resource annotations.

Buy Now
Questions 8

A user has set up a global service as a Kubernetes user with access to clusters in a Cilium Cluster Mesh. They notice that all traffic is going to remote backend pods. What is a possible explanation?

Options:

A.

There are no local endpoints matching the selector for the service.

B.

The cluster is not part of the Cilium Cluster Mesh.

C.

The service.cilium.io/affinity: "none" annotation Is set on the service.

D.

The service.cilium.io/shared: "false" annotation is set on the service.

Buy Now
Questions 9

What would be a benefit of using remote service affinity in a Cluster Mesh deployment?

Options:

A.

It would enable operators to avoid the unavailability of an application by temporarily forwarding traffic to local clusters while the remote application is being updated.

B.

It would enable operators to avoid the unavailability of an application by using the Egress Gateway to send the traffic to a remote destination.

C.

It would enable operators to avoid the unavailability of an application by load-balancing traffic to all endpolnts across both local and remote clusters.

D.

It would enable operators to avoid the unavailability of an application by temporarily forwarding traffic to remote clusters while the local application is being updated.

Buy Now
Questions 10

You must add Hubble to your Kubernetes cluster where Cilium is NOT the installed CNI. Your cluster is already running in production and you must minimise downtime.

Which method is the most appropriate?

Options:

A.

Install Cilium in chaining mode and then enable Hubble.

B.

Install Hubble in the existing cluster as Hubble can be deployed without Cilium.

C.

Migrate your workloads into Cilium and Hubble.

D.

Create a cluster with Cilium and Hubble installed and switch clusters.

Buy Now
Questions 11

Which component, when available, is able to handle IPAM requests?

Options:

A.

Cilium Agent

B.

Cilium API Server

C.

Cilium Operator

D.

Cilium CNIPIugin

Buy Now
Questions 12

What is the default policy enforcement behavior?

Options:

A.

If any rule selects an Endpoint and the rule has an ingress section, the Endpoint goes Into default deny at egress. f any rule selects an Endpoint and the rule has an egress section, the Endpoint goes into default deny at ingress.

B.

If any rule selects an Endpoint and the rule has an ingress section, the Endpoint goes Into default allow at egress, f any rule selects an Endpoint and the rule has an egress section, the Endpoint goes into default allow at ingress.

C.

If any rule selects an Endpoint and the rule has an ingress section, the Endpoint goes Into default allow at Ingress, f any rule selects an Endpoint and the rule has an egress section, the Endpoint goes into default allow at egress.

D.

If any rule selects an Endpoint and the rule has an ingress section, the Endpoint goes into default deny at ingress. f any rule selects an Endpoint and the rule has an egress section, the Endpoint goes into default deny at egress.

Buy Now
Questions 13

What is true about Layer 7 protocol visibility in Cilium?

Options:

A.

DNS visibility in available in the ingress direction only.

B.

It can be enabled by deploying a standard Kubernetes network policy.

C.

It results in traffic being proxied through an Envoy instance.

D.

It supports any Layer 7 protocols, including SSH, Telnet and FTP.

Buy Now
Questions 14

Which affirmation is true about eBPF host-routing?

Options:

A.

eBPF host-routing ensures that traffic is distributed evenly across multiple backend services, improving the overall efficiency of load balancing.

B.

eBPF host-routing allows the network stack to prepare larger GSO (transmit) and GRO (receive) packets to reduce the number of times the stack is traversed, which improves performance and latency.

C.

eBPF host-routing allows bypassing iptables and upper stack overhead in the host namespace and some context-switching overhead when traversing through the Virtual Ethernet pairs.

D.

eBPF host-routing is particularly suitable when pods are exposed behind Kubernetes Services, which face external clients from the Internet.

Buy Now
Questions 15

What is the issue with the following egress gateway manifest specification?

Cilium-Associate Question 15

Egress gateway manifest exhibit

Options:

A.

The manifest cannot specify both an interface and an egress IP.

B.

Cilium egress gateway manifests only support one label selector.

C.

The egress IP must be taken from a public IP address CIDR.

D.

Only interfaces named eth* can be used with Cilium egress gateway

Buy Now
Questions 16

You need to expose an application over HTTPS on your Cilium-managed Kubernetes cluster

The security team has specifically asked for traffic to be encrypted all the way from the external clients to the Service.

Which option should you use?

Options:

A.

Enable the Gateway API feature and use the TLS Terminate mode and HTTPRoute route type.

B.

Enable the Ingress feature and use the TLS Passthrough mode and TLSRoute route type.

C.

Enable the Ingress feature and use the TLS Terminate mode and HTTPRoute route type.

D.

Enable the Gateway API feature and use the TLS Passthrough mode and TLSRoute route type.

Buy Now
Exam Code: Cilium-Associate
Exam Name: Cilium Certified AssociateCCA
Last Update: Sep 20, 2026
Questions: 60

PDF + Testing Engine

$55.71   $185.69

Testing Engine

$42.85   $142.83

PDF (Q&A)

$47.13   $157.11