KCSA - Kubernetes and Cloud Security Associate Cluster Practice Questions
The free KCSA - Kubernetes and Cloud Security Associate questions that deal with cluster, with answers and explanations. The full bank and the timed practice test cover every topic the exam asks about.
Question #3
In a Kubernetes cluster, what are the security risks associated with using ConfigMaps for storing secrets?
Correct answer: B
Explanation
ConfigMaps are explicitly not for confidential data. Exact extract (ConfigMap concept):"A ConfigMap is an API object used to store non-confidential data in key-value pairs." Exact extract (ConfigMap concept):"ConfigMaps are not intended to hold confidential data. Use a Secret for confidential data." Why this is risky:data placed into a ConfigMap is stored as regular (plaintext) string values in the API and etcd (unless you deliberately use binaryData for base64 content you supply). That means if someone has read access to the namespace or to etcd/APIServer storage, they can view the values. Secrets vs ConfigMaps (to clarify distractor D): Exact extract (Secret concept):"By default, secret data is stored as unencrypted base64-encoded strings.You canenable encryption at restto protect Secrets stored in etcd." This base64 behavior applies toSecrets, not to ConfigMap data. Thus optionDis incorrect for ConfigMaps. About RBAC (to clarify distractor A):Kubernetesdoessupport fine-grained RBAC forbothConfigMaps and Secrets; the issue isn't lack of RBAC but that ConfigMaps arenotdesigned for confidential material. About compatibility (to clarify distractor C):Using ConfigMaps for secrets doesn't make apps "incompatible"; it's simplyinsecureand against guidance. [References:, Kubernetes Docs —ConfigMaps: https://kubernetes.io/docs/concepts/configuration/configmap/, Kubernetes Docs —Secrets: https://kubernetes.io/docs/concepts/configuration/secret/, Kubernetes Docs —Encrypting Secret Data at Rest: https://kubernetes.io/docs/tasks/administer- cluster/encrypt-data/, Note: The citations above are from the official Kubernetes documentation and reflect the stated guidance that ConfigMaps are fornon- confidentialdata, while Secrets (with encryption at rest enabled) are forconfidentialdata, and that the 4C's map todefense in depth., ]
Question #6
A container running in a Kubernetes cluster has permission to modify host processes on the underlying node. What combination of privileges and capabilities is most likely to have led to this privilege escalation?
Correct answer: B
Explanation
hostPID:When enabled, the container shares the host's process namespace ?? container can see and potentially interact with host processes. SYS_PTRACE capability:Grants the container the ability to trace, inspect, and modify other processes (e.g., via ptrace). Combination of hostPID + SYS_PTRACE allows a container toattach to and modify host processes, which is a direct privilege escalation. Other options explained: hostPath + AUDIT_WRITE:hostPath exposes filesystem paths but does not inherently allow process modification. hostNetwork + NET_RAW:grants raw socket access but only for networking, not host process modification. A:Incorrect — such combinationsdo exist(like B). [References:, Kubernetes Docs — Configure a Pod to use hostPID: https://kubernetes.io/docs/tasks/configure-pod-container/share-process-namespace/, Linux Capabilities man page: https://man7.org/linux/man-pages/man7/capabilities.7.html, ]
Question #7
When using a cloud provider's managed Kubernetes service, who is responsible for maintaining the etcd cluster?
Correct answer: C
Explanation
Inmanaged Kubernetes services(EKS, GKE, AKS), the control plane is operated by thecloud provider. This includesetcd, API server, controller manager, scheduler. Users manageworker nodes(in some models) and workloads, but not the control plane. Exact extract (GKE Docs): "The control plane, including the API server and etcd database, is managed and maintained by Google." Similarly forEKSandAKS, etcd is fully managed by the provider. [References:, GKE Architecture: https://cloud.google.com/kubernetes-engine/docs/concepts/cluster-architecture, EKS Architecture: https://docs.aws.amazon.com/eks/latest/userguide/eks-architecture.html, AKS Docs: https://learn.microsoft.com/en-us/azure/aks/concepts-clusters-workloads, ]
Question #8
An attacker has access to the network segment that the cluster is on. What happens when a compromised Pod attempts to connect to the API server?
Correct answer: C
Explanation
By default,Pods can connect to the API server(since ServiceAccount tokens are mounted). However, whether they succeed in acting depends on: Network Policies(may block egress). RBAC(controls permissions). Exact extract (Kubernetes Docs – API Access): ??Pods authenticate to the API server using the service account token mounted into the Pod. Authorization is then enforced by RBAC. NetworkPolicies may further restrict access.?? Clarifications: A: No default automatic isolation. B: Not always unrestricted; policies may apply. D: Pods get minimal default privileges, not automatic elevation. References: Kubernetes Docs — API Access to Pods: https://kubernetes.io/docs/concepts/security/service-accounts/ Kubernetes Docs — Network Policies: https://kubernetes.io/docs/concepts/services-networking/network- policies/
Question #10
What is the reasoning behind considering the Cloud as the trusted computing base of a Kubernetes cluster?
Correct answer: D
Explanation
The4C's of Cloud Native Security(Cloud, Cluster, Container, Code) model starts withCloudas the base layer. If the Cloud (infrastructure layer) is compromised, every higher layer (Cluster, Container, Code) inherits that compromise. Exact extract (Kubernetes Security Overview): ??The 4C's of Cloud Native security are Cloud, Clusters, Containers, and Code. You can think of the 4C's as a layered approach. A Kubernetes cluster can only be as secure as the cloud infrastructure it is deployed on.?? This means the cloud is part of thetrusted computing baseof a Kubernetes cluster. References: Kubernetes Docs — Security Overview (4C's): https://kubernetes.io/docs/concepts/security/overview/#the- 4cs-of-cloud-native-security
Continue with KCSA - Kubernetes and Cloud Security Associate
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in KCSA - Kubernetes and Cloud Security Associate, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
All KCSA - Kubernetes and Cloud Security Associate practice questions →
