Step2Study
IT & TechnologyKCNA100% Free

Kubernetes and Cloud Native Associate (KCNA)

Practice bank
230 Qs
Real exam
60 Qs
Time limit
90 min
Passing
A passing score of 75% or higher is required.

Exam blueprint

Kubernetes Fundamentals
40%
Cloud Native Architecture
20%
Cloud Native Security
15%
Cloud Native Observability
15%
Cloud Native Delivery
10%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 135 min · pass 75% · 230 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Kubernetes and Cloud Native Associate (KCNA) practice test questions

Sample questions from the 230-question bank, with answers and explanations.

All questions
  1. 1. A team is using Git to manage their application code and Kubernetes manifests. They want to implement a workflow where the entire state of their Kubernetes cluster is described declaratively in Git, and any changes in Git are automatically applied to the cluster, while also ensuring the cluster's actual state never drifts from the Git-defined desired state. What is this operational model called?

    Cloud Native Delivery

    • A. GitOps
    • B. Trunk-based development
    • C. Feature branching
    • D. Shift-left testing
    Show answer

    A. GitOps

    GitOps is an operational framework that takes DevOps best practices used for application development (like version control, collaboration, CI/CD) and applies them to infrastructure automation. It uses Git as the single source of truth for declarative infrastructure and applications, with automated tools to reconcile the actual state with the desired state in Git.

  2. 2. A software company uses Kubernetes for its microservices architecture. They have a complex database system that requires specific provisioning, backup, and scaling logic that is not natively supported by Kubernetes deployments. To manage this database consistently and robustly, which Kubernetes extension pattern should they implement?

    Cloud Native Delivery

    • A. Sidecar Container
    • B. Custom Resource Definition (CRD)
    • C. Admission Controller
    • D. Operator
    Show answer

    D. Operator

    A Kubernetes Operator extends the Kubernetes API to automate the management of complex applications, such as databases, by encoding human operational knowledge into software. It uses Custom Resources to manage specific application instances.

  3. 3. A development team is deploying a new microservice to a Kubernetes cluster. They need a standardized, repeatable way to define, install, and upgrade even complex Kubernetes applications. Which cloud-native tool is best suited for this purpose?

    Cloud Native Delivery

    • A. Prometheus
    • B. Envoy
    • C. Fluentd
    • D. Helm
    Show answer

    D. Helm

    Helm is a package manager for Kubernetes that allows developers to define, install, and upgrade applications using charts. This provides a standardized and repeatable process for managing Kubernetes deployments.

  4. 4. A financial institution is deploying a critical banking application on Kubernetes. Due to strict regulatory compliance and security policies, they need to ensure that only approved container images from trusted sources can be used in their deployments. Which Cloud Native component is essential for centralizing and enforcing this policy?

    Cloud Native Delivery

    • A. A Kubernetes Ingress controller
    • B. A private container registry
    • C. A Helm chart repository
    • D. A public Docker Hub repository
    Show answer

    B. A private container registry

    A private container registry allows organizations to store, manage, and secure their own approved container images. This provides granular control over image access, scanning, and provenance, which is crucial for compliance and security in regulated environments.

  5. 5. A financial institution is deploying a critical banking application on Kubernetes. Due to strict compliance requirements and data residency laws, they cannot use public container registries. Which type of registry should they use to store their application images securely?

    Cloud Native Delivery

    • A. Google Container Registry
    • B. Docker Hub
    • C. Private Container Registry
    • D. Quay.io
    Show answer

    C. Private Container Registry

    A private container registry allows organizations to host their container images within their own infrastructure or a dedicated, secure environment, ensuring compliance with strict security and data residency requirements.

  6. 6. A large enterprise is migrating its legacy applications to a cloud-native platform using Kubernetes. Many of these applications rely on custom, stateful resources that require specific initialization, lifecycle management, and disaster recovery procedures. The enterprise wants to automate these complex operations within Kubernetes itself, rather than relying on external scripts or manual processes. Which Kubernetes extension would provide the most robust and integrated solution for this challenge?

    Cloud Native Delivery

    • A. Pod Security Policies
    • B. Ingress Controllers
    • C. Custom Resource Definitions (CRDs) with an Operator
    • D. Network Policies
    Show answer

    C. Custom Resource Definitions (CRDs) with an Operator

    Custom Resource Definitions (CRDs) allow defining new resource types in Kubernetes, while an Operator provides the control logic to manage the lifecycle of instances of these custom resources, automating complex operational tasks for stateful applications.

  7. 7. A company is using a private container registry to store its Docker images. They have a CI/CD pipeline that builds new images for their microservices. After an image is built, it needs to be made available for deployment to Kubernetes clusters in various environments (dev, staging, prod). What is the next logical step in the CI/CD pipeline after a container image is successfully built and tagged?

    Cloud Native Delivery

    • A. Deploy the application directly to production.
    • B. Push the image to the container registry.
    • C. Generate a Helm chart for the application.
    • D. Run unit tests on the application code.
    Show answer

    B. Push the image to the container registry.

    After a container image is successfully built and tagged, the next logical step in the CI/CD pipeline is to push it to a container registry. This makes the image persistently stored, versioned, and accessible to other parts of the pipeline (like deployment tools) and different environments.

  8. 8. A development team is deploying a new microservice to a Kubernetes cluster. They need a standardized way to package, share, and deploy their application, including all its Kubernetes resources like Deployments, Services, and ConfigMaps. Which Cloud Native tool is specifically designed for this purpose?

    Cloud Native Delivery

    • A. Fluentd
    • B. Helm
    • C. Prometheus
    • D. Argo CD
    Show answer

    B. Helm

    Helm is the package manager for Kubernetes, enabling developers to define, install, and upgrade even complex Kubernetes applications using charts. It standardizes the packaging and deployment process.

  9. 9. A team is using Git to manage their application code and Kubernetes manifests. They want to ensure that all changes to the production environment are made exclusively through Git commits and pull requests, and that the actual state of the cluster continuously converges with the desired state defined in Git. Which operational model are they following?

    Cloud Native Delivery

    • A. Waterfall Model
    • B. GitOps
    • C. Feature Branching
    • D. Trunk-Based Development
    Show answer

    B. GitOps

    GitOps is an operational framework that takes DevOps best practices like version control, collaboration, and CI/CD, and applies them to infrastructure automation. It uses Git as the single source of truth for declarative infrastructure and applications.

  10. 10. A DevOps team is setting up a new CI/CD pipeline for a microservices application. They want to ensure that every code commit automatically triggers a process to build, test, and validate the code before it is integrated into the main branch. Which stage of the CI/CD pipeline does this describe?

    Cloud Native Delivery

    • A. Continuous Deployment
    • B. Continuous Integration
    • C. Continuous Monitoring
    • D. Continuous Delivery
    Show answer

    B. Continuous Integration

    Continuous Integration (CI) is the practice where developers frequently merge their code changes into a central repository, after which automated builds and tests are run. This helps detect integration errors early.

  11. 11. A startup is building a new application and wants to automate the process of provisioning and managing its underlying infrastructure (servers, networks, databases) in a cloud environment. They aim for consistency, repeatability, and version control for their infrastructure. Which practice is most suitable for achieving this?

    Cloud Native Delivery

    • A. Manual Configuration
    • B. Bash Scripting
    • C. Virtual Machine Templates
    • D. Infrastructure as Code (IaC)
    Show answer

    D. Infrastructure as Code (IaC)

    Infrastructure as Code (IaC) is the practice of managing and provisioning infrastructure through code instead of manual processes. This allows for version control, consistency, and repeatability in environment setup.

  12. 12. A startup is building a new application and wants to automate the process of provisioning the underlying cloud infrastructure (e.g., virtual machines, networks, databases) consistently and repeatedly. They aim to treat infrastructure like application code, storing its definition in a version control system. Which approach aligns with this goal?

    Cloud Native Delivery

    • A. Containerization of infrastructure services
    • B. Shell scripting for one-time setup
    • C. Manual provisioning via cloud provider console
    • D. Infrastructure as Code (IaC)
    Show answer

    D. Infrastructure as Code (IaC)

    Infrastructure as Code (IaC) is the practice of managing and provisioning computing infrastructure through machine-readable definition files, rather than physical hardware configuration or interactive configuration tools. It enables version control, automation, and consistent environments.

  13. 13. A developer is working on a new feature branch for a Kubernetes application. To deploy and test this feature in an isolated environment, they need to quickly provision a full set of Kubernetes resources, including a Deployment, Service, and Ingress, with specific configurations for their branch. Which tool helps them achieve this consistent and repeatable deployment of multiple related resources?

    Cloud Native Delivery

    • A. Helm chart installation
    • B. kubectl apply -f deployment.yaml
    • C. Kustomize patch
    • D. Docker Compose
    Show answer

    A. Helm chart installation

    Helm charts are designed to package and deploy a collection of related Kubernetes resources as a single unit. They support templating and value overrides, making it easy to deploy the same application with different configurations (e.g., for different branches or environments) in a repeatable manner.

  14. 14. A team is developing a new microservice and wants to store its Docker image in a registry. They've decided to use a registry that is hosted by their cloud provider and integrated with their existing identity and access management (IAM) solution. Which type of container registry are they most likely using?

    Cloud Native Delivery

    • A. A cloud-provider managed private registry
    • B. A local Docker daemon registry
    • C. A self-hosted open-source registry like Harbor
    • D. A public, unauthenticated registry
    Show answer

    A. A cloud-provider managed private registry

    Cloud-provider managed private registries (like AWS ECR, Google Container Registry/Artifact Registry, or Azure Container Registry) offer seamless integration with the cloud provider's IAM, security features, and often have better performance and reliability than self-hosted or local options.

  15. 15. A software company uses Kubernetes for its microservices architecture. They have a complex stateful application that requires specialized setup, lifecycle management, and disaster recovery procedures that are beyond standard Kubernetes Deployments. To automate and encapsulate this operational knowledge, which Cloud Native pattern should they implement?

    Cloud Native Delivery

    • A. A Kubernetes Operator
    • B. A ConfigMap with startup scripts
    • C. A Helm chart with pre-install hooks
    • D. A custom `kubectl` plugin
    Show answer

    A. A Kubernetes Operator

    Kubernetes Operators are applications that extend the Kubernetes API to create, configure, and manage instances of complex applications. They encapsulate human operational knowledge for specific applications, handling stateful logic, upgrades, backups, and more, making them ideal for complex stateful applications.

  16. 16. A team is designing a CI/CD pipeline for a Kubernetes application. They want to ensure that once the code passes all automated tests and is deemed production-ready, it is automatically deployed to the production environment without any manual intervention. Which stage of the CI/CD pipeline enables this full automation to production?

    Cloud Native Delivery

    • A. Continuous Deployment
    • B. Continuous Delivery
    • C. Continuous Testing
    • D. Continuous Integration
    Show answer

    A. Continuous Deployment

    Continuous Deployment (CD) extends Continuous Delivery by automatically releasing every change that passes the automated pipeline into production. This eliminates manual intervention for production releases.

  17. 17. A large enterprise is migrating its legacy applications to a cloud-native platform using Kubernetes. They encounter numerous applications that require complex, application-specific Day-2 operations like scaling based on custom metrics, intelligent backups, and seamless upgrades. Simply using standard Kubernetes Deployment manifests is insufficient. Which advanced Cloud Native pattern offers the best solution for automating these complex operational tasks?

    Cloud Native Delivery

    • A. Using Helm charts with `post-install` and `pre-upgrade` hooks for custom logic.
    • B. Developing custom `kubectl` plugins to execute specific operational scripts.
    • C. Implementing Kubernetes Operators using Custom Resource Definitions (CRDs).
    • D. Leveraging Kubernetes `Jobs` and `CronJobs` for scheduled operational tasks.
    Show answer

    C. Implementing Kubernetes Operators using Custom Resource Definitions (CRDs).

    Kubernetes Operators are designed to automate complex, application-specific operational knowledge (Day-2 operations) by extending the Kubernetes API with Custom Resources and custom controllers. They manage the entire lifecycle of an application, including scaling, backups, upgrades, and failure recovery, which is beyond the scope of simple hooks or jobs.

  18. 18. A team is designing a CI/CD pipeline for a Kubernetes application. They want to ensure that once a new Docker image is built and pushed to the container registry, the Kubernetes cluster automatically updates the running application to use this new image. Which CI/CD strategy is most aligned with this automated deployment goal?

    Cloud Native Delivery

    • A. Continuous Delivery (CD)
    • B. Continuous Integration (CI)
    • C. Continuous Deployment (CD)
    • D. Manual Deployment
    Show answer

    C. Continuous Deployment (CD)

    Continuous Deployment (CD) automates the entire process from code commit to production deployment, including the automatic release of every validated change to users. This means that once an image is ready, the system automatically updates the running application in production, without human intervention.

  19. 19. A DevOps team is setting up a new CI/CD pipeline for a microservices application. They want to ensure that every code change triggers an automated build, test, and potentially a deployment process. What is the primary purpose of the 'Continuous Integration' (CI) part of a CI/CD pipeline?

    Cloud Native Delivery

    • A. To perform manual security audits on code before release.
    • B. To monitor application performance and user experience in real-time.
    • C. To automatically deploy validated code to production environments.
    • D. To continuously merge code changes from multiple developers into a shared repository and verify them.
    Show answer

    D. To continuously merge code changes from multiple developers into a shared repository and verify them.

    Continuous Integration (CI) is the practice of frequently merging code changes into a central repository, followed by automated builds and tests. Its primary purpose is to detect integration errors early and ensure the codebase remains in a healthy, deployable state.

  20. 20. A company is implementing a CI/CD pipeline for its cloud-native applications. They want to ensure that all changes to application code and infrastructure configurations are version-controlled, traceable, and subject to review before deployment. Which foundational practice, central to modern CI/CD, best supports these requirements?

    Cloud Native Delivery

    • A. Canary Releases
    • B. Blue/Green Deployments
    • C. Git-based Workflow
    • D. Feature Flagging
    Show answer

    C. Git-based Workflow

    A Git-based workflow ensures that all code and configuration changes are stored in a Git repository, providing version control, a complete history, and mechanisms for pull requests and code reviews, which are essential for traceability and quality in CI/CD.

  21. 21. A security engineer is setting up a new Kubernetes cluster and wants to ensure that all administrative actions on the cluster are logged and auditable. Specifically, they need to track who performed which action, when, and from where, to aid in forensic investigations and compliance. Which Kubernetes component is primarily responsible for generating these audit logs?

    Cloud Native Security

    • A. Kubelet
    • B. Kube-proxy
    • C. API Server
    • D. Controller Manager
    Show answer

    C. API Server

    The Kubernetes API Server is the central management component of the cluster and is responsible for processing all API requests. It generates comprehensive audit logs that record all administrative and user actions, which are essential for security monitoring, compliance, and forensic analysis.

  22. 22. A security engineer is tasked with preventing privilege escalation attacks within containers in a Kubernetes environment. Specifically, they want to ensure that no container can gain root privileges on the host node or access sensitive kernel features. Which Linux security primitive is fundamental to isolating processes and their capabilities within a container?

    Cloud Native Security

    • A. cgroups
    • B. iptables
    • C. SELinux
    • D. namespaces
    Show answer

    D. namespaces

    Linux namespaces are the core mechanism that provides process isolation for containers, giving each container its own view of system resources like PIDs, network interfaces, and user IDs, preventing escape to the host's root.

  23. 23. An organization is adopting a policy to ensure that all container images deployed in their Kubernetes clusters are free from known vulnerabilities. They want to integrate this check into their CI/CD pipeline, failing builds if any critical vulnerabilities are detected before an image is pushed to the registry. Which security practice does this scenario primarily describe?

    Cloud Native Security

    • A. Secrets Management
    • B. Runtime Security Monitoring
    • C. Shift-Left Security
    • D. Network Segmentation
    Show answer

    C. Shift-Left Security

    Shift-Left Security emphasizes incorporating security practices and testing earlier in the development lifecycle (e.g., CI/CD pipeline). Detecting vulnerabilities before images are even pushed to a registry is a prime example of shifting security left.

  24. 24. A security engineer is implementing a strategy to prevent software supply chain attacks in a Kubernetes environment. They want to ensure that only container images signed by an approved authority can be deployed to the cluster. Which component of the Kubernetes security ecosystem is primarily responsible for enforcing this type of image signature validation?

    Cloud Native Security

    • A. Pod Security Admission (PSA)
    • B. ImagePullSecrets
    • C. Admission Controllers (specifically a Validating Admission Webhook)
    • D. Role-Based Access Control (RBAC)
    Show answer

    C. Admission Controllers (specifically a Validating Admission Webhook)

    Admission Controllers, particularly Validating Admission Webhooks, are custom extensions that can intercept requests to the Kubernetes API server *before* an object is persisted. This makes them ideal for enforcing policies like image signature validation, where the deployment of an unsigned image needs to be prevented.

  25. 25. A security architect is designing a multi-tenant Kubernetes cluster. To ensure strong isolation and prevent privilege escalation, they want to prevent Pods from running as root, using host namespaces, or accessing sensitive host paths. Which Kubernetes admission controller is specifically designed to enforce these types of Pod-level security best practices?

    Cloud Native Security

    • A. LimitRange
    • B. ResourceQuota
    • C. NodeRestriction
    • D. Pod Security Admission (PSA)
    Show answer

    D. Pod Security Admission (PSA)

    Pod Security Admission (PSA) is a built-in Kubernetes admission controller that enforces Pod Security Standards (PSS). PSS defines three levels (Privileged, Baseline, Restricted) that directly address the requirements like preventing root execution, host namespace usage, and host path access, ensuring strong Pod-level security.

Kubernetes and Cloud Native Associate (KCNA) flashcards

Tap a card to flip it. 136 flashcards in the full deck.

  • GitOps

    Flip card

    An operational framework that uses Git as the single source of truth for declarative infrastructure and applications. Changes to the desired state in Git are automatically applied to the target environment, and reconciliation ensures actual state matches desired state.

    • Git is the single source of truth for declarative configurations.
    • Automated agents continuously reconcile the cluster's actual state with Git's desired state.
    • Provides an audit trail for all changes to infrastructure and applications.
    Study this card →
  • Kubernetes Operator

    Flip card

    A Kubernetes Operator is software that extends Kubernetes functionality by automating the management of complex, stateful applications using Custom Resources and Controllers.

    • Automates operational tasks like provisioning, scaling, and backups.
    • Encodes human operational knowledge into code.
    • Uses Custom Resources (CRs) and Custom Resource Definitions (CRDs).
    Study this card →
  • Helm Charts

    Flip card

    Helm Charts are packages of pre-configured Kubernetes resources that can be deployed as a single unit, simplifying application management.

    • Defines, installs, and upgrades Kubernetes applications.
    • Uses YAML-based templates for resource definitions.
    • Manages application dependencies and configurations.
    Study this card →
  • Private Container Registry

    Flip card

    A centralized, secure repository for storing and managing container images within an organization, offering enhanced control, security, and compliance over image provenance and access.

    • Provides granular access control for sensitive images.
    • Enables vulnerability scanning and policy enforcement.
    • Supports air-gapped or restricted network environments.
    Study this card →
  • Operator with CRDs

    Flip card

    Kubernetes Operators, built upon Custom Resource Definitions (CRDs), extend the Kubernetes API to automate the management of complex stateful applications by encoding operational knowledge into software.

    • CRDs define new API objects for custom resources.
    • Operators provide the intelligence to manage these custom resources.
    • Automate complex tasks like provisioning, scaling, backup, and recovery.
    Study this card →
  • Container Image Push

    Flip card

    The action of uploading a built and tagged container image to a container registry, making it available for storage, distribution, and subsequent deployment to runtime environments.

    • Stores the immutable image in a centralized repository.
    • Enables versioning and tracking of images.
    • Makes images accessible to Kubernetes clusters and other deployment tools.
    Study this card →
  • Continuous Integration (CI)

    Flip card

    Continuous Integration is a development practice where developers merge code changes frequently into a central repository, after which automated builds and tests are run.

    • Automates build and test processes.
    • Detects integration issues early.
    • Requires frequent code commits.
    Study this card →
  • Infrastructure as Code (IaC)

    Flip card

    Infrastructure as Code (IaC) is the practice of managing and provisioning computing infrastructure through machine-readable definition files, rather than physical hardware configuration or interactive configuration tools.

    • Treats infrastructure configuration like application code.
    • Enables version control, automation, and consistency.
    • Supports declarative and imperative approaches.
    Study this card →
  • Helm for Application Packaging

    Flip card

    Helm serves as a package manager for Kubernetes, allowing developers to define, install, and upgrade even complex Kubernetes applications using 'charts' that bundle all necessary resources and configurations.

    • Packages multiple Kubernetes resources (Deployment, Service, ConfigMap, etc.) into a single unit.
    • Uses templates to allow customization via values.
    • Simplifies repeatable deployments across different environments.
    Study this card →
  • Cloud-Provider Managed Registry

    Flip card

    A private container registry service offered and managed by a cloud provider (e.g., AWS ECR, GCR, ACR), deeply integrated with their platform's security, IAM, and networking services.

    • Offers high availability and scalability without self-hosting overhead.
    • Integrates with cloud IAM for granular access control.
    • Often includes built-in vulnerability scanning and image signing.
    Study this card →
  • Continuous Deployment (CD)

    Flip card

    Continuous Deployment is a software release process that uses automated testing to validate if changes are ready for release, and then automatically deploys them to production.

    • Automates the entire software release process.
    • Requires robust automated testing.
    • Eliminates manual intervention for production releases.
    Study this card →
  • Kubernetes Operator (Advanced)

    Flip card

    An Operator is a software extension to Kubernetes that makes use of custom resources to manage applications and their components. Operators follow Kubernetes principles, notably the control loop, to automate Day-2 operations for complex, stateful applications.

    • Automates Day-2 operations: upgrades, backups, scaling, recovery.
    • Extends Kubernetes API with Custom Resource Definitions (CRDs).
    • Continuously reconciles desired state with actual state.
    Study this card →
  • Git-based Workflow

    Flip card

    A development practice where all code, configuration, and artifacts are managed and version-controlled within a Git repository, enabling collaboration, traceability, and automated processes.

    • Serves as the single source of truth for all project assets.
    • Facilitates collaboration through branching and merging.
    • Provides a complete history of changes for auditing and rollback.
    Study this card →
  • Kubernetes API Server Audit Logs

    Flip card

    Detailed records generated by the Kubernetes API Server that track all requests made to the cluster, including who made the request, when, from where, and what action was performed, crucial for security and compliance.

    • Records all authenticated requests to the API Server.
    • Captures user, timestamp, source IP, and resource accessed.
    • Essential for security monitoring, forensic analysis, and compliance.
    Study this card →
  • Linux Namespaces

    Flip card

    A feature of the Linux kernel that partitions kernel resources such that a process or set of processes has its own isolated view of the global system resources.

    • Fundamental for container isolation.
    • Each namespace type isolates a specific resource (PID, network, user, mount, UTS, IPC).
    • Prevents processes from seeing or interacting with resources outside their namespace.
    Study this card →
  • Shift-Left Security

    Flip card

    An approach to security that integrates security practices and testing earlier in the software development lifecycle (SDLC), aiming to identify and mitigate vulnerabilities as early as possible.

    • Moves security from the end to the beginning of the SDLC.
    • Reduces cost and effort of fixing vulnerabilities.
    • Includes practices like SAST, DAST, image scanning in CI/CD.
    Study this card →
  • Kubernetes Admission Controllers

    Flip card

    Components that intercept requests to the Kubernetes API server after authentication and authorization, but before persistence to the object store, to modify or validate objects.

    • Can be Mutating (modify objects) or Validating (reject objects).
    • Webhooks allow external services to implement custom admission logic.
    • Crucial for enforcing security policies like image validation, resource quotas, etc.
    Study this card →
  • Pod Security Admission (PSA)

    Flip card

    A built-in Kubernetes admission controller that enforces Pod Security Standards (PSS) on Pods, ensuring they adhere to predefined security policies.

    • Enforces 'Privileged', 'Baseline', and 'Restricted' security standards.
    • Can be configured at the namespace level to 'enforce', 'audit', or 'warn'.
    • Directly addresses common Pod security misconfigurations.
    Study this card →
  • Service Mesh for Security

    Flip card

    A dedicated infrastructure layer that handles service-to-service communication, providing capabilities like traffic management, observability, and robust security features such as mutual TLS (mTLS) and fine-grained access control.

    • Encrypts inter-service communication (mTLS).
    • Enforces Layer 7 (application layer) policies.
    • Provides centralized control over network security within the cluster.
    Study this card →
  • Kubernetes API Server

    Flip card

    The central component of the Kubernetes control plane that exposes the Kubernetes API. It is responsible for serving the API, authenticating requests, authorizing access, and validating data.

    • Entry point for all cluster communication.
    • Handles authentication and authorization.
    • Validates and processes API requests.
    Study this card →
  • Container Runtime Security

    Flip card

    The practice of protecting containers during their execution phase by monitoring for suspicious activities, enforcing policies, and preventing unauthorized actions.

    • Focuses on active threat detection.
    • Monitors system calls, file access, network activity.
    • Can enforce policies to stop malicious behavior.
    Study this card →
  • Shift-Left Security (SAST)

    Flip card

    A DevSecOps principle that advocates for integrating security practices and testing early in the software development lifecycle, such as using Static Application Security Testing (SAST) to analyze code for vulnerabilities.

    • Identifies vulnerabilities in source code before execution.
    • Helps developers fix issues early, reducing cost and effort.
    • Part of a proactive security strategy in CI/CD.
    Study this card →
  • Kubernetes Role-Based Access Control (RBAC)

    Flip card

    A method of regulating access to computer or network resources based on the roles of individual users within an enterprise. In Kubernetes, it uses Roles/ClusterRoles and RoleBindings/ClusterRoleBindings to grant permissions.

    • Uses Roles to define permissions.
    • Uses RoleBindings to grant Roles to subjects (users, service accounts).
    • Enforces least privilege by granting only necessary access.
    Study this card →
  • Pod Security Standards (PSS)

    Flip card

    A set of predefined security policies in Kubernetes that define different levels of Pod isolation and restriction, from highly permissive to highly restrictive, to help users enforce security best practices.

    • Three levels: Privileged, Baseline, Restricted.
    • Enforced by Pod Security Admission (PSA).
    • Helps prevent common security vulnerabilities in Pods.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.