Kubernetes and Cloud Native Associate (KCNA) practice questions
230 free questions with answers and explanations.
- 51.A security auditor is reviewing a Kubernetes cluster's secrets management strategy. They find that all sensitive data, such as API keys and database credentials, are stored directly in Kubernetes Secrets objects. While these are base64 encoded, the auditor highlights a significant security weakness regarding their protection at rest within the `etcd` datastore. What is the primary concern the auditor is likely raising?Cloud Native Security
- 52.A security team is implementing a strategy to detect and respond to anomalous behavior within running containers in a Kubernetes cluster. They want to identify activities like unauthorized process execution, file system tampering, or unexpected network connections. Which category of security tools is best suited for this type of real-time monitoring and threat detection?Cloud Native Security
- 53.A development team is deploying a new application to a Kubernetes cluster. They want to ensure that all container images used in their deployments originate from an approved, scanned registry and have not been tampered with since being built. Which security control directly addresses this requirement by verifying the integrity and origin of container images before they are allowed to run?Cloud Native Security
- 54.A security auditor is reviewing a Kubernetes cluster's network policies. They observe that a critical microservice, running in the 'backend' namespace, needs to accept incoming connections only from pods in the 'frontend' namespace and from a specific external IP range (192.0.2.0/24). All other ingress traffic should be denied. Which NetworkPolicy configuration snippet correctly enforces this requirement?Cloud Native Security
- 55.A security engineer is evaluating the effectiveness of their secrets management strategy in Kubernetes. They notice that some applications are still relying on environment variables to consume sensitive data directly from Kubernetes Secrets. While better than hardcoding, this approach has a specific security drawback compared to mounting Secrets as files in a volume. What is this primary drawback?Cloud Native Security
- 56.A security engineer is configuring a Kubernetes cluster to enforce strict security policies for all new Pods. They want to ensure that no Pod runs as root, has privileged access, or mounts host paths. This policy must be enforced at the cluster level, preventing non-compliant Pods from even being created. Which Kubernetes feature is designed for this purpose?Cloud Native Security
- 57.A security auditor is reviewing a Kubernetes cluster's secrets management strategy. They find that while secrets are stored natively in Kubernetes, there is no additional encryption layer for these secrets when they are at rest within the etcd datastore. Which security control is missing to enhance the protection of these secrets?Cloud Native Security
- 58.A security engineer is implementing a strategy to prevent malicious processes within containers from making unauthorized system calls to the underlying Linux kernel. They want to restrict the set of available system calls for specific applications to only those absolutely necessary for their operation. Which Linux security mechanism is most effective for achieving this fine-grained control?Cloud Native Security
- 59.A security engineer is configuring Pod Security Admission (PSA) for a new Kubernetes namespace. They want to ensure that all Pods deployed in this namespace adhere to a baseline level of security, preventing common privilege escalation techniques while allowing some flexibility for applications. Which PSA enforcement mode should be applied to the namespace?Cloud Native Security
- 60.A containerized application experiences a security incident where a malicious process attempts to modify the root filesystem. The security team wants to ensure that, by default, all containers run with a read-only root filesystem to prevent such tampering. Which setting in the Pod's securityContext should be configured to achieve this?Cloud Native Security
- 61.A security operations team wants to implement a strategy to detect and respond to suspicious activities within their Kubernetes cluster, such as unauthorized process execution, file integrity violations, or attempts to access sensitive kernel modules from containers. They need a tool that can monitor container runtime behavior and generate alerts for anomalies. Which type of security solution is most appropriate for this requirement?Cloud Native Security
- 62.A security engineer is investigating a potential compromise. They suspect an attacker might be trying to exploit a kernel vulnerability from within a container. To mitigate such risks, the engineer wants to restrict the system calls a container can make to only those absolutely necessary for its operation. Which Linux security mechanism should they use?Cloud Native Security
- 63.A security engineer is tasked with preventing privilege escalation attacks within containers in a Kubernetes environment. Specifically, they want to ensure that no container can gain root privileges on the host node or access sensitive kernel features. Which Linux security primitive is fundamental to isolating processes and their capabilities within a container?Cloud Native Security
- 64.A developer needs to configure a Pod to access a cloud provider's API for object storage. Instead of hardcoding API keys or using Kubernetes Secrets directly, the organization prefers to leverage the cloud provider's Identity and Access Management (IAM) roles linked to Kubernetes Service Accounts. What is the primary benefit of using this approach for credential management compared to storing static credentials in Secrets?Cloud Native Security
- 65.A company is adopting a DevSecOps approach and wants to integrate security scanning into their CI/CD pipeline for Kubernetes deployments. They need to scan container images for known vulnerabilities *before* they are pushed to a registry and *before* deployment. Which phase of the software supply chain would this type of scanning primarily fall under?Cloud Native Security
- 66.An incident response team discovers that a compromised container in their Kubernetes cluster has managed to perform actions outside its intended scope, potentially affecting other containers on the same node. The team wants to understand how the container was initially isolated and what mechanisms could have prevented this lateral movement. Which Linux kernel feature is primarily responsible for isolating processes and resources (like filesystems, network interfaces, and process IDs) between containers?Cloud Native Security
- 67.A platform team is configuring Role-Based Access Control (RBAC) for a new developer team in a Kubernetes cluster. The developers need to be able to deploy new Pods, view logs of their own Pods, and update Deployments within their designated namespace. However, they should NOT be able to delete namespaces or modify cluster-wide resources. Which RBAC resource type should the platform team primarily use to define these permissions, and then bind them to the developer's ServiceAccounts or Users?Cloud Native Security
- 68.A security engineer is setting up a new Kubernetes cluster and wants to ensure that all administrative actions on the cluster are logged and auditable. Specifically, they need to track who performed which action, when, and from where, to aid in forensic investigations and compliance. Which Kubernetes component is primarily responsible for generating these audit logs?Cloud Native Security
- 69.A development team is using a GitOps workflow to manage their Kubernetes deployments. They want to ensure that all changes to their cluster configuration, including RBAC roles and network policies, are reviewed, approved, and version-controlled. Which security principle does this practice primarily support?Cloud Native Security
- 70.A security architect is designing a multi-tenant Kubernetes cluster. To ensure strong isolation and prevent privilege escalation, they want to prevent Pods from running as root, using host namespaces, or accessing sensitive host paths. Which Kubernetes admission controller is specifically designed to enforce these types of Pod-level security best practices?Cloud Native Security
- 71.A platform team is configuring Role-Based Access Control (RBAC) for a new developer team in a Kubernetes cluster. The new team needs to be able to create, view, update, and delete (CRUD) Pods, Deployments, and Services within their designated namespace, 'dev-team-a', but should not be able to manage cluster-wide resources or modify RBAC roles themselves. Which Kubernetes RBAC object should be primarily used to grant these permissions?Cloud Native Security
- 72.An incident response team is investigating a potential compromise. They suspect an attacker might have gained access to a container and is attempting to move laterally within the cluster by exploiting a vulnerability that allows them to interact with the underlying host kernel. Which Linux kernel feature is designed to restrict the system calls a process can make, thereby mitigating such privilege escalation attempts?Cloud Native Security
- 73.An incident response team is investigating a potential compromise where an attacker gained access to a container and is attempting to escalate privileges by exploiting vulnerabilities in the underlying host kernel. They suspect the attacker is trying to break out of the container's isolation. Which Linux kernel mechanism provides the fundamental isolation that prevents a process in one container from seeing or interacting with processes, network interfaces, or filesystems of the host or other containers by default?Cloud Native Security
- 74.A development team is preparing to deploy a new critical microservice to a production Kubernetes cluster. They are concerned about potential supply chain attacks, specifically the risk of compromised container images. Which security measure should they prioritize to ensure that only trusted and verified container images are deployed?Cloud Native Security
- 75.A security engineer is implementing a secrets management solution for a Kubernetes cluster. The goal is to ensure that application secrets are encrypted at rest, rotated regularly, and only accessible by authorized workloads. Which of the following best describes the principle of 'secrets encryption at rest' in this context?Cloud Native Security
- 76.A security incident response team discovers that a compromised container in their Kubernetes cluster exploited a vulnerability to gain root privileges on the host node. To mitigate this type of attack vector in the future, they want to implement a mechanism that isolates the container's processes and filesystem from the host more effectively, even if the container user is root. Which Linux kernel security feature, often leveraged by container runtimes, provides this enhanced isolation?Cloud Native Security
- 77.A large enterprise is implementing a new Kubernetes cluster with multiple development teams. Each team requires access to specific cloud provider resources (e.g., S3 buckets, database services) from their applications running in Pods. The security team insists on using a solution that avoids embedding long-lived credentials directly into Pods or container images. Which security pattern should they implement to securely grant Pods access to these external cloud resources?Cloud Native Security
- 78.A critical application in a Kubernetes cluster needs to access an external Key Management System (KMS) to retrieve database credentials. The application's Pod should not store the credentials directly, nor should it have long-lived static credentials for the KMS. Which secure method allows the Pod to authenticate to the KMS and fetch secrets dynamically?Cloud Native Security
- 79.A security operations team wants to implement a strategy to detect and respond to suspicious activities and potential threats *within* running containers and on Kubernetes nodes. This includes monitoring for unauthorized process execution, file integrity changes, and network anomalies that might indicate a compromise. Which cloud-native security approach is specifically designed to address these concerns?Cloud Native Security
- 80.A security engineer is configuring a Kubernetes cluster to enforce strict security policies for all Pods. They want to ensure that Pods cannot run as a privileged user, cannot use host namespaces, and must use a read-only root filesystem. Which Kubernetes security mechanism, configured at the namespace or cluster level, is designed to enforce these kinds of baseline security standards?Cloud Native Security
- 81.A development team is designing a new microservices application where each service is deployed in its own container. They want to ensure that new deployments of a service can be tested with a small percentage of live traffic before fully rolling out to all users, allowing for quick rollback if issues are detected. Which deployment strategy is most appropriate for this scenario?Cloud Native Architecture
- 82.A financial services company is building a new real-time fraud detection system using a microservices architecture. They need to ensure that transactions are processed quickly and reliably, and that any issues can be identified and resolved without affecting other services. The team plans to use a mechanism to isolate failures and prevent them from cascading across the system. Which pattern is most suitable for this requirement?Cloud Native Architecture
- 83.A team is designing a highly available, fault-tolerant microservices application. They want to ensure that even if a critical database service experiences a temporary outage, the dependent services do not crash or become unresponsive indefinitely, but instead gracefully degrade or retry later. Which resilience pattern is most appropriate for preventing cascading failures in this scenario?Cloud Native Architecture
- 84.A software development team wants to automate the process of building, testing, and deploying their cloud-native application. They aim for frequent, small releases and want to ensure that every code change that passes automated tests is automatically released to a production-like environment. What practice are they implementing?Cloud Native Architecture
- 85.A development team is building a new cloud-native application that consists of several independent microservices. They want to ensure that these services can communicate with each other efficiently and securely, regardless of the underlying networking complexities. They also need to implement features like traffic management, policy enforcement, and mutual TLS without modifying the application code. Which architectural component would best fulfill these requirements?Cloud Native Architecture
- 86.A platform team is designing an API Gateway for a suite of financial microservices. They need to implement rate limiting, authentication, and request routing based on the URL path, all before requests reach the individual backend services. Which feature of an API Gateway directly enables dynamic request routing to different services based on the incoming request's path?Cloud Native Architecture
- 87.A global e-commerce company is migrating its legacy monolithic application to a cloud-native microservices architecture. They need a component that can act as a single entry point for all client requests, handle authentication and authorization, perform request routing to different backend services, and potentially implement rate limiting and caching. Which architectural component fulfills these diverse requirements most comprehensively?Cloud Native Architecture
- 88.A cloud-native development team is deploying a new service to Kubernetes. They want to ensure that application configuration data, such as database connection strings or feature flags, is decoupled from the application code and can be easily updated without rebuilding the container image. Which Kubernetes object is best suited for storing non-sensitive configuration data?Cloud Native Architecture
- 89.A cloud-native development team is deploying a new service to Kubernetes. They want to ensure that the application's configuration, such as database connection strings and API keys, is managed securely and separately from the application code. This configuration needs to be injected into the running containers at runtime without rebuilding the Docker image. Which Kubernetes-native object is designed for this purpose?Cloud Native Architecture
- 90.A startup is building a new application and wants to minimize operational overhead for managing the underlying infrastructure, focusing solely on writing code. They anticipate highly variable traffic patterns, requiring automatic scaling up and down to handle demand spikes and lulls. Which cloud-native compute model would be most suitable for this scenario?Cloud Native Architecture
- 91.A development team is designing a new microservices application where each service is deployed independently. To minimize risk during updates, they want to introduce a new version of a service to a small subset of users before rolling it out to everyone. This allows them to monitor performance and catch issues with minimal impact. Which deployment strategy are they planning to use?Cloud Native Architecture
- 92.A development team is implementing a new cloud-native application that uses multiple microservices. They want to ensure that all changes to the application's infrastructure and configuration are version-controlled, auditable, and can be automatically applied to the production environment. Which cloud-native architectural pattern best supports these requirements?Cloud Native Architecture
- 93.A team is developing a highly available, fault-tolerant microservices application. They want to prevent a single failing downstream service from overwhelming an upstream service with continuous requests, which could lead to resource exhaustion and cascading failures. Which resilience pattern should they implement to automatically stop calls to a failing service after a certain threshold?Cloud Native Architecture
- 94.A financial institution is deploying a highly sensitive payment processing microservice. They need to ensure that all traffic between this service and other internal services is encrypted, authenticated, and authorized, without requiring developers to embed complex security logic into each service's code. Which cloud native component can transparently enforce these security policies for inter-service communication?Cloud Native Architecture
- 95.A global e-commerce company is migrating its legacy monolithic application to a cloud-native microservices architecture. They need a centralized entry point for all external clients to access their various backend services, handle authentication, rate limiting, and request routing across multiple services. Which cloud-native component is designed for this purpose?Cloud Native Architecture
- 96.A team is developing a new cloud-native application that consists of several independent microservices. They want to ensure that these services can communicate with each other securely and reliably, without requiring each developer to implement complex networking and security logic within their service code. Which architectural component would best address these concerns?Cloud Native Architecture
- 97.A cloud-native application processes sensitive user data across multiple microservices. To meet compliance requirements and enhance security, the development team needs to ensure that all service-to-service communication within the cluster is encrypted and authenticated at the transport layer, without relying on application-level encryption. Which service mesh feature should they enable?Cloud Native Architecture
- 98.A development team is implementing a CI/CD pipeline for their cloud-native application. They want to ensure that every code change that passes automated tests is automatically deployed to a staging environment, but requires a manual approval step before deployment to production. Which CI/CD practice does this scenario best describe?Cloud Native Architecture
- 99.A platform team is designing an API Gateway for a suite of financial microservices. They need to ensure that incoming requests are routed to the correct backend service based on the URL path. For example, requests to `/api/v1/accounts` should go to the 'accounts' service, and `/api/v1/transactions` should go to the 'transactions' service. What routing strategy should the API Gateway employ?Cloud Native Architecture
- 100.A development team is implementing a new microservices-based application. They want to ensure that changes to the application's infrastructure and configuration are treated with the same rigor as application code, allowing for version control, automated deployments, and rollbacks. Which cloud native architectural pattern best addresses this requirement?Cloud Native Architecture