Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

KCSA Kubernetes and Cloud Native Security Associate (KCSA) Questions and Answers

Questions 4

Which of the following statements regarding a container run with privileged: true is correct?

Options:

A.

A container run with privileged: true within a cluster can access all Secrets used within that cluster.

B.

A container run with privileged: true within a Namespace can access all Secrets used within that Namespace.

C.

A container run with privileged: true on a node can access all Secrets used on that node.

D.

A container run with privileged: true has no additional access to Secrets than if it were run with privileged: false.

Buy Now
Questions 5

Which of the following statements best describes the role of the Scheduler in Kubernetes?

Options:

A.

The Scheduler is responsible for monitoring and managing the health of the Kubernetes cluster.

B.

The Scheduler is responsible for ensuring the security of the Kubernetes cluster and its components.

C.

The Scheduler is responsible for managing the deployment and scaling of applications in the Kubernetes cluster.

D.

The Scheduler is responsible for assigning Pods to nodes based on resource availability and other constraints.

Buy Now
Questions 6

Which label should be added to the Namespace to block any privileged Pods from being created in that Namespace?

Options:

A.

privileged: false

B.

privileged: true

C.

pod-security.kubernetes.io/enforce: baseline

D.

pod.security.kubernetes.io/privileged: false

Buy Now
Questions 7

Which of the following statements correctly describes a container breakout?

Options:

A.

A container breakout is the process of escaping the container and gaining access to the Pod's network traffic.

B.

A container breakout is the process of escaping a container when it reaches its resource limits.

C.

A container breakout is the process of escaping the container and gaining access to the cloud provider's infrastructure.

D.

A container breakout is the process of escaping the container and gaining access to the host operating system.

Buy Now
Questions 8

Which information does a user need to verify a signed container image?

Options:

A.

The image's SHA-256 hash and the private key of the signing authority.

B.

The image's digital signature and the private key of the signing authority.

C.

The image's SHA-256 hash and the public key of the signing authority.

D.

The image's digital signature and the public key of the signing authority.

Buy Now
Questions 9

What is Grafana?

Options:

A.

A cloud-native distributed tracing system for monitoring microservices architectures.

B.

A container orchestration platform for managing and scaling applications.

C.

A platform for monitoring and visualizing time-series data.

D.

A cloud-native security tool for scanning and detecting vulnerabilities in Kubernetes clusters.

Buy Now
Questions 10

What information is stored in etcd?

Options:

A.

Etcd manages the configuration data, state data, and metadata for Kubernetes.

B.

Application logs and monitoring data for auditing and troubleshooting purposes.

C.

Sensitive user data such as usernames and passwords.

D.

Pod data contained in Persistent Volume Claims (e.g. hostPath).

Buy Now
Questions 11

How can a user enforce the Pod Security Standard without third-party tools?

Options:

A.

Through implementing Kyverno or OPA Policies.

B.

Use the PodSecurity admission controller.

C.

It is only possible to enforce the Pod Security Standard with additional tools within the cloud native ecosystem.

D.

No additional measures have to be taken to enforce the Pod Security Standard.

Buy Now
Questions 12

How do Kubernetes namespaces impact the application of policies when using Pod Security Admission?

Options:

A.

Namespaces are ignored; Pod Security Admission policies apply cluster-wide only.

B.

Different policies can be applied to specific namespaces.

C.

Each namespace can have only one active policy.

D.

The default namespace enforces the strictest security policies by default.

Buy Now
Questions 13

As a Kubernetes and Cloud Native Security Associate, a user can set up audit logging in a cluster. What is the risk of logging every event at the full RequestResponse level?

Options:

A.

No risk, as it provides the most comprehensive audit trail.

B.

Increased storage requirements and potential impact on performance.

C.

Improved security and easier incident investigation.

D.

Reduced storage requirements and faster performance.

Buy Now
Questions 14

In a Kubernetes cluster, what are the security risks associated with using ConfigMaps for storing secrets?

Options:

A.

Storing secrets in ConfigMaps does not allow for fine-grained access control via RBAC.

B.

Storing secrets in ConfigMaps can expose sensitive information as they are stored in plaintext and can be accessed by unauthorized users.

C.

Using ConfigMaps for storing secrets might make applications incompatible with the Kubernetes cluster.

D.

ConfigMaps store sensitive information in etcd encoded in base64 format automatically, which does not ensure confidentiality of data.

Buy Now
Questions 15

A container image is trojanized by an attacker by compromising the build server. Based on the STRIDE threat modeling framework, which threat category best defines this threat?

Options:

A.

Repudiation

B.

Spoofing

C.

Denial of Service

D.

Tampering

Buy Now
Questions 16

You are responsible for securing the kubelet component in a Kubernetes cluster.

Which of the following statements about kubelet security is correct?

Options:

A.

Kubelet runs as a privileged container by default.

B.

Kubelet does not have any built-in security features.

C.

Kubelet supports TLS authentication and encryption for secure communication with the API server.

D.

Kubelet requires root access to interact with the host system.

Buy Now
Questions 17

On a client machine, what directory (by default) contains sensitive credential information?

Options:

A.

/etc/kubernetes/

B.

$HOME/.kube

C.

/opt/kubernetes/secrets/

D.

$HOME/.config/kubernetes/

Buy Now
Questions 18

In a cluster that contains Nodes with multiple container runtimes installed, how can a Pod be configured to be created on a specific runtime?

Options:

A.

By using a command-line flag when creating the Pod.

B.

By modifying the Docker daemon configuration.

C.

By setting the container runtime as an environment variable in the Pod.

D.

By specifying the container runtime in the Pod's YAML file.

Buy Now
Exam Code: KCSA
Exam Name: Kubernetes and Cloud Native Security Associate (KCSA)
Last Update: May 31, 2026
Questions: 60

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11