Kubernetes and Cloud Native Associate (KCNA) practice questions

230 free questions with answers and explanations.

Practice test
  1. 1.A team is using Git to manage their application code and Kubernetes manifests. They want to ensure that all changes to the production environment are made exclusively through Git commits and pull requests, and that the actual state of the cluster continuously converges with the desired state defined in Git. Which operational model are they following?Cloud Native Delivery
  2. 2.A large enterprise is migrating its legacy applications to a cloud-native platform using Kubernetes. They encounter numerous applications that require complex, application-specific Day-2 operations like scaling based on custom metrics, intelligent backups, and seamless upgrades. Simply using standard Kubernetes Deployment manifests is insufficient. Which advanced Cloud Native pattern offers the best solution for automating these complex operational tasks?Cloud Native Delivery
  3. 3.A software company uses Kubernetes for its microservices architecture. They have a complex stateful application that requires specialized setup, lifecycle management, and disaster recovery procedures that are beyond standard Kubernetes Deployments. To automate and encapsulate this operational knowledge, which Cloud Native pattern should they implement?Cloud Native Delivery
  4. 4.A startup is building a new application and wants to automate the process of provisioning and managing its underlying infrastructure (servers, networks, databases) in a cloud environment. They aim for consistency, repeatability, and version control for their infrastructure. Which practice is most suitable for achieving this?Cloud Native Delivery
  5. 5.A software company uses Kubernetes for its microservices architecture. They have a complex database system that requires specific provisioning, backup, and scaling logic that is not natively supported by Kubernetes deployments. To manage this database consistently and robustly, which Kubernetes extension pattern should they implement?Cloud Native Delivery
  6. 6.A team is designing a CI/CD pipeline for a Kubernetes application. They want to ensure that once the code passes all automated tests and is deemed production-ready, it is automatically deployed to the production environment without any manual intervention. Which stage of the CI/CD pipeline enables this full automation to production?Cloud Native Delivery
  7. 7.A company is using a private container registry to store its Docker images. They have a CI/CD pipeline that builds new images for their microservices. After an image is built, it needs to be made available for deployment to Kubernetes clusters in various environments (dev, staging, prod). What is the next logical step in the CI/CD pipeline after a container image is successfully built and tagged?Cloud Native Delivery
  8. 8.A team is developing a new microservice and wants to store its Docker image in a registry. They've decided to use a registry that is hosted by their cloud provider and integrated with their existing identity and access management (IAM) solution. Which type of container registry are they most likely using?Cloud Native Delivery
  9. 9.A DevOps team is setting up a new CI/CD pipeline for a microservices application. They want to ensure that every code change triggers an automated build, test, and potentially a deployment process. What is the primary purpose of the 'Continuous Integration' (CI) part of a CI/CD pipeline?Cloud Native Delivery
  10. 10.A startup is building a new application and wants to automate the process of provisioning the underlying cloud infrastructure (e.g., virtual machines, networks, databases) consistently and repeatedly. They aim to treat infrastructure like application code, storing its definition in a version control system. Which approach aligns with this goal?Cloud Native Delivery
  11. 11.A financial institution is deploying a critical banking application on Kubernetes. Due to strict regulatory compliance and security policies, they need to ensure that only approved container images from trusted sources can be used in their deployments. Which Cloud Native component is essential for centralizing and enforcing this policy?Cloud Native Delivery
  12. 12.A team is using Git to manage their application code and Kubernetes manifests. They want to implement a workflow where the entire state of their Kubernetes cluster is described declaratively in Git, and any changes in Git are automatically applied to the cluster, while also ensuring the cluster's actual state never drifts from the Git-defined desired state. What is this operational model called?Cloud Native Delivery
  13. 13.A financial institution is deploying a critical banking application on Kubernetes. Due to strict compliance requirements and data residency laws, they cannot use public container registries. Which type of registry should they use to store their application images securely?Cloud Native Delivery
  14. 14.A development team is deploying a new microservice to a Kubernetes cluster. They need a standardized way to package, share, and deploy their application, including all its Kubernetes resources like Deployments, Services, and ConfigMaps. Which Cloud Native tool is specifically designed for this purpose?Cloud Native Delivery
  15. 15.A development team is deploying a new microservice to a Kubernetes cluster. They need a standardized, repeatable way to define, install, and upgrade even complex Kubernetes applications. Which cloud-native tool is best suited for this purpose?Cloud Native Delivery
  16. 16.A large enterprise is migrating its legacy applications to a cloud-native platform using Kubernetes. Many of these applications rely on custom, stateful resources that require specific initialization, lifecycle management, and disaster recovery procedures. The enterprise wants to automate these complex operations within Kubernetes itself, rather than relying on external scripts or manual processes. Which Kubernetes extension would provide the most robust and integrated solution for this challenge?Cloud Native Delivery
  17. 17.A DevOps team is setting up a new CI/CD pipeline for a microservices application. They want to ensure that every code commit automatically triggers a process to build, test, and validate the code before it is integrated into the main branch. Which stage of the CI/CD pipeline does this describe?Cloud Native Delivery
  18. 18.A developer is working on a new feature branch for a Kubernetes application. To deploy and test this feature in an isolated environment, they need to quickly provision a full set of Kubernetes resources, including a Deployment, Service, and Ingress, with specific configurations for their branch. Which tool helps them achieve this consistent and repeatable deployment of multiple related resources?Cloud Native Delivery
  19. 19.A team is designing a CI/CD pipeline for a Kubernetes application. They want to ensure that once a new Docker image is built and pushed to the container registry, the Kubernetes cluster automatically updates the running application to use this new image. Which CI/CD strategy is most aligned with this automated deployment goal?Cloud Native Delivery
  20. 20.A company is implementing a CI/CD pipeline for its cloud-native applications. They want to ensure that all changes to application code and infrastructure configurations are version-controlled, traceable, and subject to review before deployment. Which foundational practice, central to modern CI/CD, best supports these requirements?Cloud Native Delivery
  21. 21.A development team is using a GitOps workflow to manage their Kubernetes deployments. They want to ensure that all changes to their cluster configuration, including RBAC roles and network policies, are reviewed, approved, and version-controlled. Which security principle does this practice primarily support?Cloud Native Security
  22. 22.A large enterprise uses multiple Kubernetes clusters across different cloud providers. They need a centralized and consistent way to manage and inject sensitive credentials, such as API keys and database passwords, into their applications without storing them directly in Kubernetes Secrets objects or configuration files. This solution must also integrate with existing enterprise secret stores. Which approach is best suited for this scenario?Cloud Native Security
  23. 23.A financial institution is deploying a highly sensitive application to Kubernetes. They require a robust identity and access management (IAM) solution that integrates with their existing enterprise directory and provides fine-grained authorization for Kubernetes resources based on user roles and attributes. Which component within Kubernetes is primarily responsible for enforcing these authorization rules?Cloud Native Security
  24. 24.A development team is deploying a new application to a Kubernetes cluster. To enhance the security posture of their container images, they decide to implement a process that cryptographically verifies the origin and integrity of all images before deployment. Which of the following cloud-native security practices directly addresses this requirement?Cloud Native Security
  25. 25.An incident response team is investigating a potential compromise where a malicious actor might have gained access to a Kubernetes node and tampered with the container runtime configuration, potentially enabling insecure features or backdoors. Which component of the Kubernetes security model is primarily responsible for ensuring the integrity and authenticity of the host's configuration and software, including the container runtime, from boot-up?Cloud Native Security
  26. 26.A platform engineering team is setting up a new Kubernetes cluster and needs to implement a custom security policy: all Pods must have a specific security context configured, disallowing privilege escalation and ensuring read-only root filesystems. They want this policy to be automatically enforced for all new Pods, and any Pods failing to meet this standard should be rejected. Which Kubernetes component should they use to achieve this enforcement?Cloud Native Security
  27. 27.A developer needs to configure a custom application running in a Pod to access an external Key Management System (KMS) for cryptographic operations. The application requires credentials to authenticate with the KMS. Following secure practices, how should these credentials be securely provided to the Pod without embedding them directly in the container image or configuration files?Cloud Native Security
  28. 28.A security architect is designing a multi-tenant Kubernetes cluster. To ensure strong isolation and prevent privilege escalation, they want to limit the capabilities available to containers, disallow privileged containers, and restrict sensitive hostPath mounts. Which Kubernetes security primitive, when configured via an Admission Controller, is specifically designed to enforce these types of pod-level security constraints?Cloud Native Security
  29. 29.A security team wants to implement a comprehensive strategy for protecting sensitive data within their Kubernetes cluster. They decide to use a dedicated external secrets management system (e.g., HashiCorp Vault, AWS Secrets Manager) instead of relying solely on native Kubernetes Secrets. What is the primary benefit of this approach compared to using only Kubernetes native Secrets?Cloud Native Security
  30. 30.A security auditor is reviewing the access controls for a Kubernetes cluster. They notice that several service accounts and user roles have been granted broad permissions, such as `cluster-admin` or `edit` on all namespaces, even for applications that only require access to specific resources in a single namespace. This configuration significantly increases the potential blast radius in case of a compromise. Which fundamental security principle is being violated in this scenario?Cloud Native Security
  31. 31.A containerized application experiences a security incident where a malicious process attempts to modify the root filesystem. The security team wants to ensure that, by default, all containers run with a read-only root filesystem to prevent such tampering. Which setting in the Pod's securityContext should be configured to achieve this?Cloud Native Security
  32. 32.A security operations team wants to implement a strategy to detect and respond to suspicious activities within their Kubernetes cluster, such as unauthorized process execution, file integrity violations, or attempts to access sensitive kernel modules from containers. They need a tool that can monitor container runtime behavior and generate alerts for anomalies. Which type of security solution is most appropriate for this requirement?Cloud Native Security
  33. 33.A security engineer is implementing a strategy to prevent malicious processes from making unexpected system calls within a container. They want to define a whitelist of allowed system calls for specific applications, blocking any calls outside this predefined set. Which Linux security mechanism is specifically designed for this purpose?Cloud Native Security
  34. 34.A financial institution is deploying a highly sensitive application to a Kubernetes cluster. To meet stringent compliance requirements, they need to ensure that all network traffic between microservices within the cluster is encrypted and that access policies are enforced at the application layer (Layer 7), including mutual TLS (mTLS) for authentication. Which cloud-native security solution is best suited to fulfill these requirements?Cloud Native Security
  35. 35.An organization is adopting a policy to ensure that all container images deployed in their Kubernetes clusters are free from known vulnerabilities. They want to integrate this check into their CI/CD pipeline, failing builds if any critical vulnerabilities are detected before an image is pushed to the registry. Which security practice does this scenario primarily describe?Cloud Native Security
  36. 36.A security engineer is investigating a potential compromise. They suspect an attacker might be trying to exploit a kernel vulnerability from within a container. To mitigate such risks, the engineer wants to restrict the system calls a container can make to only those absolutely necessary for its operation. Which Linux security mechanism should they use?Cloud Native Security
  37. 37.A large organization uses multiple Kubernetes clusters across different cloud providers. They need a unified solution for managing and distributing secrets (e.g., database passwords, API keys) that can integrate with their existing enterprise Key Management System (KMS) and provide features like secret rotation and auditing. Which solution pattern is most appropriate for this scenario?Cloud Native Security
  38. 38.A security engineer is configuring Pod Security Admission (PSA) for a new Kubernetes namespace. They want to ensure that all Pods deployed in this namespace adhere to a baseline level of security, preventing common privilege escalation techniques while allowing some flexibility for applications. Which PSA enforcement mode should be applied to the namespace?Cloud Native Security
  39. 39.A development team is deploying a new application to a Kubernetes cluster. They want to ensure that all container images used in their deployments originate from an approved, scanned registry and have not been tampered with since being built. Which security control directly addresses this requirement by verifying the integrity and origin of container images before they are allowed to run?Cloud Native Security
  40. 40.A security engineer is evaluating the effectiveness of their secrets management strategy in Kubernetes. They notice that some applications are still relying on environment variables to consume sensitive data directly from Kubernetes Secrets. While better than hardcoding, this approach has a specific security drawback compared to mounting Secrets as files in a volume. What is this primary drawback?Cloud Native Security
  41. 41.A security auditor is reviewing a Kubernetes cluster's secrets management strategy. They find that sensitive API keys are stored directly as plain text within Kubernetes Secret objects, and these objects are frequently accessed by multiple applications. Which best practice is being violated, and what is its primary risk?Cloud Native Security
  42. 42.A company is adopting a DevSecOps approach and wants to integrate security scanning into their CI/CD pipeline for Kubernetes deployments. They need to scan container images for known vulnerabilities *before* they are pushed to a registry and *before* deployment. Which phase of the software supply chain would this type of scanning primarily fall under?Cloud Native Security
  43. 43.A security engineer is configuring a Kubernetes cluster to enforce strict security policies for all new Pods. They want to ensure that no Pod runs as root, has privileged access, or mounts host paths. This policy must be enforced at the cluster level, preventing non-compliant Pods from even being created. Which Kubernetes feature is designed for this purpose?Cloud Native Security
  44. 44.A platform team is configuring Role-Based Access Control (RBAC) for a new developer team in a Kubernetes cluster. The developers need to be able to deploy new Pods, view logs of their own Pods, and update Deployments within their designated namespace. However, they should NOT be able to delete namespaces or modify cluster-wide resources. Which RBAC resource type should the platform team primarily use to define these permissions, and then bind them to the developer's ServiceAccounts or Users?Cloud Native Security
  45. 45.A development team is deploying a new microservice to a Kubernetes cluster. They need to ensure that sensitive database credentials are securely managed and only accessible by the specific microservice that requires them, without being hardcoded into the application's container image or configuration files. Which Kubernetes native object is best suited for this requirement?Cloud Native Security
  46. 46.A large enterprise is implementing a custom security policy that requires all container images deployed in their Kubernetes clusters to originate from an internal, trusted image registry and be scanned for vulnerabilities within the last 24 hours. This policy needs to be enforced automatically at deployment time. Which Kubernetes extensibility mechanism, often paired with an external policy engine, is best suited to enforce this dynamic, custom policy?Cloud Native Security
  47. 47.A security auditor is reviewing a Kubernetes cluster's secrets management strategy. They find that all sensitive data, such as API keys and database credentials, are stored directly in Kubernetes Secrets objects. While these are base64 encoded, the auditor highlights a significant security weakness regarding their protection at rest within the `etcd` datastore. What is the primary concern the auditor is likely raising?Cloud Native Security
  48. 48.A platform engineering team is setting up a new Kubernetes cluster and needs to define custom security policies that go beyond standard Pod Security Standards (PSS). Specifically, they want to disallow deployments that use a root filesystem and require all container images to be from a specific internal registry. Which Kubernetes extension point is most suitable for enforcing these custom rules at the point of resource creation or update?Cloud Native Security
  49. 49.A security team is investigating a potential compromise where an attacker gained access to a Kubernetes node and is attempting to extract sensitive data from Pods running on it. They want to ensure that even if an attacker gains control of a node, they cannot easily access the memory or processes of other Pods running on the same node. Which advanced isolation technology could provide an additional layer of defense by running Pods in lightweight virtual machines?Cloud Native Security
  50. 50.A security auditor is reviewing a Kubernetes cluster's secrets management strategy. They find that while secrets are stored natively in Kubernetes, there is no additional encryption layer for these secrets when they are at rest within the etcd datastore. Which security control is missing to enhance the protection of these secrets?Cloud Native Security