Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard

A development team is using a GitOps workflow to manage their Kubernetes deployments. They want to ensure that all changes to their cluster configuration, including RBAC roles and network policies, are reviewed, approved, and version-controlled. Which security principle does this practice primarily support?

  1. ASupply chain security (for configuration)
  2. BRuntime security monitoring
  3. CSecrets management
  4. DImmutable infrastructure
Show answer & explanation

Correct answer: A. Supply chain security (for configuration)

Applying GitOps principles to cluster configuration (including RBAC, network policies, etc.) extends supply chain security to infrastructure. It ensures that the 'source of truth' for configuration is version-controlled, auditable, and subject to review, protecting against unauthorized or malicious changes to the cluster's operational state.

Why the other options are wrong

  • B. Runtime security monitoring observes active systems, not the process of configuration changes.
  • C. Secrets management is about handling sensitive data, not configuration changes.
  • D. Immutable infrastructure is related to not changing deployed components, but GitOps for configuration is more about the process of change management.

Supply Chain Security (Configuration)

Extending supply chain security principles to infrastructure and configuration management, ensuring that all changes to a system's desired state (e.g., Kubernetes manifests, policies) are version-controlled, reviewed, and traceable to prevent tampering or unauthorized modifications.

  • Applies to infrastructure-as-code and configuration-as-code.
  • Ensures integrity and authenticity of configuration files.
  • Utilizes version control, peer review, and automated deployment.
  • Mitigates risks from compromised configuration or malicious insiders.

Memory trick: GitOps secures the configuration chain.

More Cloud Native Security questions