1. A team is using Git to manage their application code and Kubernetes manifests. They want to implement a workflow where the entire state of their Kubernetes cluster is described declaratively in Git, and any changes in Git are automatically applied to the cluster, while also ensuring the cluster's actual state never drifts from the Git-defined desired state. What is this operational model called?
Cloud Native Delivery
A.GitOps
B.Trunk-based development
C.Feature branching
D.Shift-left testing
Show answerAnswer
A. GitOps
GitOps is an operational framework that takes DevOps best practices used for application development (like version control, collaboration, CI/CD) and applies them to infrastructure automation. It uses Git as the single source of truth for declarative infrastructure and applications, with automated tools to reconcile the actual state with the desired state in Git.
2. A software company uses Kubernetes for its microservices architecture. They have a complex database system that requires specific provisioning, backup, and scaling logic that is not natively supported by Kubernetes deployments. To manage this database consistently and robustly, which Kubernetes extension pattern should they implement?
Cloud Native Delivery
A.Sidecar Container
B.Custom Resource Definition (CRD)
C.Admission Controller
D.Operator
Show answerAnswer
D. Operator
A Kubernetes Operator extends the Kubernetes API to automate the management of complex applications, such as databases, by encoding human operational knowledge into software. It uses Custom Resources to manage specific application instances.
3. A development team is deploying a new microservice to a Kubernetes cluster. They need a standardized, repeatable way to define, install, and upgrade even complex Kubernetes applications. Which cloud-native tool is best suited for this purpose?
Cloud Native Delivery
A.Prometheus
B.Envoy
C.Fluentd
D.Helm
Show answerAnswer
D. Helm
Helm is a package manager for Kubernetes that allows developers to define, install, and upgrade applications using charts. This provides a standardized and repeatable process for managing Kubernetes deployments.
4. A financial institution is deploying a critical banking application on Kubernetes. Due to strict regulatory compliance and security policies, they need to ensure that only approved container images from trusted sources can be used in their deployments. Which Cloud Native component is essential for centralizing and enforcing this policy?
Cloud Native Delivery
A.A Kubernetes Ingress controller
B.A private container registry
C.A Helm chart repository
D.A public Docker Hub repository
Show answerAnswer
B. A private container registry
A private container registry allows organizations to store, manage, and secure their own approved container images. This provides granular control over image access, scanning, and provenance, which is crucial for compliance and security in regulated environments.
5. A financial institution is deploying a critical banking application on Kubernetes. Due to strict compliance requirements and data residency laws, they cannot use public container registries. Which type of registry should they use to store their application images securely?
Cloud Native Delivery
A.Google Container Registry
B.Docker Hub
C.Private Container Registry
D.Quay.io
Show answerAnswer
C. Private Container Registry
A private container registry allows organizations to host their container images within their own infrastructure or a dedicated, secure environment, ensuring compliance with strict security and data residency requirements.
6. A large enterprise is migrating its legacy applications to a cloud-native platform using Kubernetes. Many of these applications rely on custom, stateful resources that require specific initialization, lifecycle management, and disaster recovery procedures. The enterprise wants to automate these complex operations within Kubernetes itself, rather than relying on external scripts or manual processes. Which Kubernetes extension would provide the most robust and integrated solution for this challenge?
Cloud Native Delivery
A.Pod Security Policies
B.Ingress Controllers
C.Custom Resource Definitions (CRDs) with an Operator
D.Network Policies
Show answerAnswer
C. Custom Resource Definitions (CRDs) with an Operator
Custom Resource Definitions (CRDs) allow defining new resource types in Kubernetes, while an Operator provides the control logic to manage the lifecycle of instances of these custom resources, automating complex operational tasks for stateful applications.
7. A company is using a private container registry to store its Docker images. They have a CI/CD pipeline that builds new images for their microservices. After an image is built, it needs to be made available for deployment to Kubernetes clusters in various environments (dev, staging, prod). What is the next logical step in the CI/CD pipeline after a container image is successfully built and tagged?
Cloud Native Delivery
A.Deploy the application directly to production.
B.Push the image to the container registry.
C.Generate a Helm chart for the application.
D.Run unit tests on the application code.
Show answerAnswer
B. Push the image to the container registry.
After a container image is successfully built and tagged, the next logical step in the CI/CD pipeline is to push it to a container registry. This makes the image persistently stored, versioned, and accessible to other parts of the pipeline (like deployment tools) and different environments.
8. A development team is deploying a new microservice to a Kubernetes cluster. They need a standardized way to package, share, and deploy their application, including all its Kubernetes resources like Deployments, Services, and ConfigMaps. Which Cloud Native tool is specifically designed for this purpose?
Cloud Native Delivery
A.Fluentd
B.Helm
C.Prometheus
D.Argo CD
Show answerAnswer
B. Helm
Helm is the package manager for Kubernetes, enabling developers to define, install, and upgrade even complex Kubernetes applications using charts. It standardizes the packaging and deployment process.
9. A team is using Git to manage their application code and Kubernetes manifests. They want to ensure that all changes to the production environment are made exclusively through Git commits and pull requests, and that the actual state of the cluster continuously converges with the desired state defined in Git. Which operational model are they following?
Cloud Native Delivery
A.Waterfall Model
B.GitOps
C.Feature Branching
D.Trunk-Based Development
Show answerAnswer
B. GitOps
GitOps is an operational framework that takes DevOps best practices like version control, collaboration, and CI/CD, and applies them to infrastructure automation. It uses Git as the single source of truth for declarative infrastructure and applications.
10. A DevOps team is setting up a new CI/CD pipeline for a microservices application. They want to ensure that every code commit automatically triggers a process to build, test, and validate the code before it is integrated into the main branch. Which stage of the CI/CD pipeline does this describe?
Cloud Native Delivery
A.Continuous Deployment
B.Continuous Integration
C.Continuous Monitoring
D.Continuous Delivery
Show answerAnswer
B. Continuous Integration
Continuous Integration (CI) is the practice where developers frequently merge their code changes into a central repository, after which automated builds and tests are run. This helps detect integration errors early.
11. A startup is building a new application and wants to automate the process of provisioning and managing its underlying infrastructure (servers, networks, databases) in a cloud environment. They aim for consistency, repeatability, and version control for their infrastructure. Which practice is most suitable for achieving this?
Cloud Native Delivery
A.Manual Configuration
B.Bash Scripting
C.Virtual Machine Templates
D.Infrastructure as Code (IaC)
Show answerAnswer
D. Infrastructure as Code (IaC)
Infrastructure as Code (IaC) is the practice of managing and provisioning infrastructure through code instead of manual processes. This allows for version control, consistency, and repeatability in environment setup.
12. A startup is building a new application and wants to automate the process of provisioning the underlying cloud infrastructure (e.g., virtual machines, networks, databases) consistently and repeatedly. They aim to treat infrastructure like application code, storing its definition in a version control system. Which approach aligns with this goal?
Cloud Native Delivery
A.Containerization of infrastructure services
B.Shell scripting for one-time setup
C.Manual provisioning via cloud provider console
D.Infrastructure as Code (IaC)
Show answerAnswer
D. Infrastructure as Code (IaC)
Infrastructure as Code (IaC) is the practice of managing and provisioning computing infrastructure through machine-readable definition files, rather than physical hardware configuration or interactive configuration tools. It enables version control, automation, and consistent environments.
13. A developer is working on a new feature branch for a Kubernetes application. To deploy and test this feature in an isolated environment, they need to quickly provision a full set of Kubernetes resources, including a Deployment, Service, and Ingress, with specific configurations for their branch. Which tool helps them achieve this consistent and repeatable deployment of multiple related resources?
Cloud Native Delivery
A.Helm chart installation
B.kubectl apply -f deployment.yaml
C.Kustomize patch
D.Docker Compose
Show answerAnswer
A. Helm chart installation
Helm charts are designed to package and deploy a collection of related Kubernetes resources as a single unit. They support templating and value overrides, making it easy to deploy the same application with different configurations (e.g., for different branches or environments) in a repeatable manner.
14. A team is developing a new microservice and wants to store its Docker image in a registry. They've decided to use a registry that is hosted by their cloud provider and integrated with their existing identity and access management (IAM) solution. Which type of container registry are they most likely using?
Cloud Native Delivery
A.A cloud-provider managed private registry
B.A local Docker daemon registry
C.A self-hosted open-source registry like Harbor
D.A public, unauthenticated registry
Show answerAnswer
A. A cloud-provider managed private registry
Cloud-provider managed private registries (like AWS ECR, Google Container Registry/Artifact Registry, or Azure Container Registry) offer seamless integration with the cloud provider's IAM, security features, and often have better performance and reliability than self-hosted or local options.
15. A software company uses Kubernetes for its microservices architecture. They have a complex stateful application that requires specialized setup, lifecycle management, and disaster recovery procedures that are beyond standard Kubernetes Deployments. To automate and encapsulate this operational knowledge, which Cloud Native pattern should they implement?
Cloud Native Delivery
A.A Kubernetes Operator
B.A ConfigMap with startup scripts
C.A Helm chart with pre-install hooks
D.A custom `kubectl` plugin
Show answerAnswer
A. A Kubernetes Operator
Kubernetes Operators are applications that extend the Kubernetes API to create, configure, and manage instances of complex applications. They encapsulate human operational knowledge for specific applications, handling stateful logic, upgrades, backups, and more, making them ideal for complex stateful applications.
16. A team is designing a CI/CD pipeline for a Kubernetes application. They want to ensure that once the code passes all automated tests and is deemed production-ready, it is automatically deployed to the production environment without any manual intervention. Which stage of the CI/CD pipeline enables this full automation to production?
Cloud Native Delivery
A.Continuous Deployment
B.Continuous Delivery
C.Continuous Testing
D.Continuous Integration
Show answerAnswer
A. Continuous Deployment
Continuous Deployment (CD) extends Continuous Delivery by automatically releasing every change that passes the automated pipeline into production. This eliminates manual intervention for production releases.
17. A large enterprise is migrating its legacy applications to a cloud-native platform using Kubernetes. They encounter numerous applications that require complex, application-specific Day-2 operations like scaling based on custom metrics, intelligent backups, and seamless upgrades. Simply using standard Kubernetes Deployment manifests is insufficient. Which advanced Cloud Native pattern offers the best solution for automating these complex operational tasks?
Cloud Native Delivery
A.Using Helm charts with `post-install` and `pre-upgrade` hooks for custom logic.
B.Developing custom `kubectl` plugins to execute specific operational scripts.
C.Implementing Kubernetes Operators using Custom Resource Definitions (CRDs).
D.Leveraging Kubernetes `Jobs` and `CronJobs` for scheduled operational tasks.
Show answerAnswer
C. Implementing Kubernetes Operators using Custom Resource Definitions (CRDs).
Kubernetes Operators are designed to automate complex, application-specific operational knowledge (Day-2 operations) by extending the Kubernetes API with Custom Resources and custom controllers. They manage the entire lifecycle of an application, including scaling, backups, upgrades, and failure recovery, which is beyond the scope of simple hooks or jobs.
18. A team is designing a CI/CD pipeline for a Kubernetes application. They want to ensure that once a new Docker image is built and pushed to the container registry, the Kubernetes cluster automatically updates the running application to use this new image. Which CI/CD strategy is most aligned with this automated deployment goal?
Cloud Native Delivery
A.Continuous Delivery (CD)
B.Continuous Integration (CI)
C.Continuous Deployment (CD)
D.Manual Deployment
Show answerAnswer
C. Continuous Deployment (CD)
Continuous Deployment (CD) automates the entire process from code commit to production deployment, including the automatic release of every validated change to users. This means that once an image is ready, the system automatically updates the running application in production, without human intervention.
19. A DevOps team is setting up a new CI/CD pipeline for a microservices application. They want to ensure that every code change triggers an automated build, test, and potentially a deployment process. What is the primary purpose of the 'Continuous Integration' (CI) part of a CI/CD pipeline?
Cloud Native Delivery
A.To perform manual security audits on code before release.
B.To monitor application performance and user experience in real-time.
C.To automatically deploy validated code to production environments.
D.To continuously merge code changes from multiple developers into a shared repository and verify them.
Show answerAnswer
D. To continuously merge code changes from multiple developers into a shared repository and verify them.
Continuous Integration (CI) is the practice of frequently merging code changes into a central repository, followed by automated builds and tests. Its primary purpose is to detect integration errors early and ensure the codebase remains in a healthy, deployable state.
20. A company is implementing a CI/CD pipeline for its cloud-native applications. They want to ensure that all changes to application code and infrastructure configurations are version-controlled, traceable, and subject to review before deployment. Which foundational practice, central to modern CI/CD, best supports these requirements?
Cloud Native Delivery
A.Canary Releases
B.Blue/Green Deployments
C.Git-based Workflow
D.Feature Flagging
Show answerAnswer
C. Git-based Workflow
A Git-based workflow ensures that all code and configuration changes are stored in a Git repository, providing version control, a complete history, and mechanisms for pull requests and code reviews, which are essential for traceability and quality in CI/CD.
21. A security engineer is setting up a new Kubernetes cluster and wants to ensure that all administrative actions on the cluster are logged and auditable. Specifically, they need to track who performed which action, when, and from where, to aid in forensic investigations and compliance. Which Kubernetes component is primarily responsible for generating these audit logs?
Cloud Native Security
A.Kubelet
B.Kube-proxy
C.API Server
D.Controller Manager
Show answerAnswer
C. API Server
The Kubernetes API Server is the central management component of the cluster and is responsible for processing all API requests. It generates comprehensive audit logs that record all administrative and user actions, which are essential for security monitoring, compliance, and forensic analysis.
22. A security engineer is tasked with preventing privilege escalation attacks within containers in a Kubernetes environment. Specifically, they want to ensure that no container can gain root privileges on the host node or access sensitive kernel features. Which Linux security primitive is fundamental to isolating processes and their capabilities within a container?
Cloud Native Security
A.cgroups
B.iptables
C.SELinux
D.namespaces
Show answerAnswer
D. namespaces
Linux namespaces are the core mechanism that provides process isolation for containers, giving each container its own view of system resources like PIDs, network interfaces, and user IDs, preventing escape to the host's root.
23. An organization is adopting a policy to ensure that all container images deployed in their Kubernetes clusters are free from known vulnerabilities. They want to integrate this check into their CI/CD pipeline, failing builds if any critical vulnerabilities are detected before an image is pushed to the registry. Which security practice does this scenario primarily describe?
Cloud Native Security
A.Secrets Management
B.Runtime Security Monitoring
C.Shift-Left Security
D.Network Segmentation
Show answerAnswer
C. Shift-Left Security
Shift-Left Security emphasizes incorporating security practices and testing earlier in the development lifecycle (e.g., CI/CD pipeline). Detecting vulnerabilities before images are even pushed to a registry is a prime example of shifting security left.
24. A security engineer is implementing a strategy to prevent software supply chain attacks in a Kubernetes environment. They want to ensure that only container images signed by an approved authority can be deployed to the cluster. Which component of the Kubernetes security ecosystem is primarily responsible for enforcing this type of image signature validation?
Cloud Native Security
A.Pod Security Admission (PSA)
B.ImagePullSecrets
C.Admission Controllers (specifically a Validating Admission Webhook)
D.Role-Based Access Control (RBAC)
Show answerAnswer
C. Admission Controllers (specifically a Validating Admission Webhook)
Admission Controllers, particularly Validating Admission Webhooks, are custom extensions that can intercept requests to the Kubernetes API server *before* an object is persisted. This makes them ideal for enforcing policies like image signature validation, where the deployment of an unsigned image needs to be prevented.
25. A security architect is designing a multi-tenant Kubernetes cluster. To ensure strong isolation and prevent privilege escalation, they want to prevent Pods from running as root, using host namespaces, or accessing sensitive host paths. Which Kubernetes admission controller is specifically designed to enforce these types of Pod-level security best practices?
Cloud Native Security
A.LimitRange
B.ResourceQuota
C.NodeRestriction
D.Pod Security Admission (PSA)
Show answerAnswer
D. Pod Security Admission (PSA)
Pod Security Admission (PSA) is a built-in Kubernetes admission controller that enforces Pod Security Standards (PSS). PSS defines three levels (Privileged, Baseline, Restricted) that directly address the requirements like preventing root execution, host namespace usage, and host path access, ensuring strong Pod-level security.
An operational framework that uses Git as the single source of truth for declarative infrastructure and applications. Changes to the desired state in Git are automatically applied to the target environment, and reconciliation ensures actual state matches desired state.
Git is the single source of truth for declarative configurations.
Automated agents continuously reconcile the cluster's actual state with Git's desired state.
Provides an audit trail for all changes to infrastructure and applications.
A Kubernetes Operator is software that extends Kubernetes functionality by automating the management of complex, stateful applications using Custom Resources and Controllers.
Automates operational tasks like provisioning, scaling, and backups.
Encodes human operational knowledge into code.
Uses Custom Resources (CRs) and Custom Resource Definitions (CRDs).
A centralized, secure repository for storing and managing container images within an organization, offering enhanced control, security, and compliance over image provenance and access.
Provides granular access control for sensitive images.
Enables vulnerability scanning and policy enforcement.
Supports air-gapped or restricted network environments.
Kubernetes Operators, built upon Custom Resource Definitions (CRDs), extend the Kubernetes API to automate the management of complex stateful applications by encoding operational knowledge into software.
CRDs define new API objects for custom resources.
Operators provide the intelligence to manage these custom resources.
Automate complex tasks like provisioning, scaling, backup, and recovery.
The action of uploading a built and tagged container image to a container registry, making it available for storage, distribution, and subsequent deployment to runtime environments.
Stores the immutable image in a centralized repository.
Enables versioning and tracking of images.
Makes images accessible to Kubernetes clusters and other deployment tools.
Continuous Integration is a development practice where developers merge code changes frequently into a central repository, after which automated builds and tests are run.
Infrastructure as Code (IaC) is the practice of managing and provisioning computing infrastructure through machine-readable definition files, rather than physical hardware configuration or interactive configuration tools.
Treats infrastructure configuration like application code.
Enables version control, automation, and consistency.
Helm serves as a package manager for Kubernetes, allowing developers to define, install, and upgrade even complex Kubernetes applications using 'charts' that bundle all necessary resources and configurations.
Packages multiple Kubernetes resources (Deployment, Service, ConfigMap, etc.) into a single unit.
Uses templates to allow customization via values.
Simplifies repeatable deployments across different environments.
A private container registry service offered and managed by a cloud provider (e.g., AWS ECR, GCR, ACR), deeply integrated with their platform's security, IAM, and networking services.
Offers high availability and scalability without self-hosting overhead.
Integrates with cloud IAM for granular access control.
Often includes built-in vulnerability scanning and image signing.
Continuous Deployment is a software release process that uses automated testing to validate if changes are ready for release, and then automatically deploys them to production.
Automates the entire software release process.
Requires robust automated testing.
Eliminates manual intervention for production releases.
An Operator is a software extension to Kubernetes that makes use of custom resources to manage applications and their components. Operators follow Kubernetes principles, notably the control loop, to automate Day-2 operations for complex, stateful applications.
A development practice where all code, configuration, and artifacts are managed and version-controlled within a Git repository, enabling collaboration, traceability, and automated processes.
Serves as the single source of truth for all project assets.
Facilitates collaboration through branching and merging.
Provides a complete history of changes for auditing and rollback.
Detailed records generated by the Kubernetes API Server that track all requests made to the cluster, including who made the request, when, from where, and what action was performed, crucial for security and compliance.
Records all authenticated requests to the API Server.
Captures user, timestamp, source IP, and resource accessed.
Essential for security monitoring, forensic analysis, and compliance.
A feature of the Linux kernel that partitions kernel resources such that a process or set of processes has its own isolated view of the global system resources.
Fundamental for container isolation.
Each namespace type isolates a specific resource (PID, network, user, mount, UTS, IPC).
Prevents processes from seeing or interacting with resources outside their namespace.
An approach to security that integrates security practices and testing earlier in the software development lifecycle (SDLC), aiming to identify and mitigate vulnerabilities as early as possible.
Moves security from the end to the beginning of the SDLC.
Reduces cost and effort of fixing vulnerabilities.
Includes practices like SAST, DAST, image scanning in CI/CD.
Components that intercept requests to the Kubernetes API server after authentication and authorization, but before persistence to the object store, to modify or validate objects.
Can be Mutating (modify objects) or Validating (reject objects).
Webhooks allow external services to implement custom admission logic.
Crucial for enforcing security policies like image validation, resource quotas, etc.
A dedicated infrastructure layer that handles service-to-service communication, providing capabilities like traffic management, observability, and robust security features such as mutual TLS (mTLS) and fine-grained access control.
Encrypts inter-service communication (mTLS).
Enforces Layer 7 (application layer) policies.
Provides centralized control over network security within the cluster.
The central component of the Kubernetes control plane that exposes the Kubernetes API. It is responsible for serving the API, authenticating requests, authorizing access, and validating data.
The practice of protecting containers during their execution phase by monitoring for suspicious activities, enforcing policies, and preventing unauthorized actions.
Focuses on active threat detection.
Monitors system calls, file access, network activity.
A DevSecOps principle that advocates for integrating security practices and testing early in the software development lifecycle, such as using Static Application Security Testing (SAST) to analyze code for vulnerabilities.
Identifies vulnerabilities in source code before execution.
Helps developers fix issues early, reducing cost and effort.
A method of regulating access to computer or network resources based on the roles of individual users within an enterprise. In Kubernetes, it uses Roles/ClusterRoles and RoleBindings/ClusterRoleBindings to grant permissions.
Uses Roles to define permissions.
Uses RoleBindings to grant Roles to subjects (users, service accounts).
Enforces least privilege by granting only necessary access.
A set of predefined security policies in Kubernetes that define different levels of Pod isolation and restriction, from highly permissive to highly restrictive, to help users enforce security best practices.
Three levels: Privileged, Baseline, Restricted.
Enforced by Pod Security Admission (PSA).
Helps prevent common security vulnerabilities in Pods.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.