Practice Exam 1
5 of this form’s 60 questions, drawn from across its domains, free. The explanation on every one of them is free too, at every tier, and always will be.
Question 1 of 5
Cloud native security lifecycleOverview of Cloud Native SecurityA team divides its runtime hardening work. Which three areas does the Runtime phase comprise?
Question 2 of 5
Controlling API accessKubernetes Cluster Component SecurityA cluster runs both RBAC and webhook authorization. What happens when one module allows a request and another denies it?
Question 3 of 5
Pod Security AdmissionKubernetes Security FundamentalsAn engineer patches a running Pod that already violates its namespace level. Which single change escapes the policy check?
Question 4 of 5
User NamespacesKubernetes Threat ModelAn engineer asks how two Pods sharing a node with user namespaces are kept apart at host level. What does the kubelet guarantee?
Question 5 of 5
Container ImagesPlatform SecurityAn engineer sets imagePullPolicy to Never for a workload on an air-gapped node. What happens when the image is not present locally?
0 of 60 completed
The other 55 questions are the rest of this form: same 90 minute clock, same 75 cut score, and the same explanation on every question, which is never behind the wall. Practice Exam 1 of 2 on KCSA.
What this exam covers
- Overview of Cloud Native Security8 questions / 14% of the exam
- Kubernetes Cluster Component Security13 questions / 22% of the exam
- Kubernetes Security Fundamentals13 questions / 22% of the exam
- Kubernetes Threat Model10 questions / 16% of the exam
- Platform Security10 questions / 16% of the exam
- Compliance and Security Frameworks6 questions / 10% of the exam
Checking what you already have access to.
Every question is original, written from the published objectives. We never reproduce, paraphrase, or imitate real exam content, and neither should anything else you study from.