Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Linux Foundation Kubernetes and Cloud Native KCSA Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam KCSA Premium Access

View all detail and faqs for the KCSA exam


716 Students Passed

94% Average Score

90% Same Questions
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

A cluster is failing to pull more recent versions of images from k8s.gcr.io. Why may this be?

Options:

A.

There is a network connectivity issue between the cluster and k8s.gcr.io.

B.

There is a bug in the container runtime or the image pull process.

C.

The authentication credentials for accessing k8s.gcr.io are incorrectly scoped.

D.

The container image registry k8s.gcr.io has been deprecated.

Questions # 12:

In a cluster that contains Nodes withmultiple container runtimesinstalled, how can a Pod be configured to be created on a specific runtime?

Options:

A.

By using a command-line flag when creating the Pod.

B.

By modifying the Docker daemon configuration.

C.

By setting the container runtime as an environment variable in the Pod.

D.

By specifying the container runtime in the Pod's YAML file.

Questions # 13:

Which step would give an attacker a foothold in a cluster butno long-term persistence?

Options:

A.

Modify Kubernetes objects stored within etcd.

B.

Modify file on host filesystem.

C.

Starting a process in a running container.

D.

Create restarting container on host using Docker.

Questions # 14:

When should soft multitenancy be used over hard multitenancy?

Options:

A.

When the priority is enabling resource sharing and efficiency between tenants.

B.

When the priority is enabling complete isolation between tenants.

C.

When the priority is enabling fine-grained control over tenant resources.

D.

When the priority is enabling strict security boundaries between tenants.

Questions # 15:

In which order are thevalidating and mutating admission controllersrun while the Kubernetes API server processes a request?

Options:

A.

The order of execution varies and is determined by the cluster configuration.

B.

Validating admission controllers run before mutating admission controllers.

C.

Validating and mutating admission controllers run simultaneously.

D.

Mutating admission controllers run before validating admission controllers.

Questions # 16:

As a Kubernetes and Cloud Native Security Associate, a user can set upaudit loggingin a cluster. What is the risk of logging every event at the fullRequestResponselevel?

Options:

A.

No risk, as it provides the most comprehensive audit trail.

B.

Increased storage requirements and potential impact on performance.

C.

Improved security and easier incident investigation.

D.

Reduced storage requirements and faster performance.

Questions # 17:

Which other controllers are part of the kube-controller-manager inside the Kubernetes cluster?

Options:

A.

Job controller, CronJob controller, and DaemonSet controller

B.

Pod, Service, and Ingress controller

C.

Namespace controller, ConfigMap controller, and Secret controller

D.

Replication controller, Endpoints controller, Namespace controller, and ServiceAccounts controller

Questions # 18:

Why does the defaultbase64 encodingthat Kubernetes applies to the contents of Secret resources provide inadequate protection?

Options:

A.

Base64 encoding is vulnerable to brute-force attacks.

B.

Base64 encoding relies on a shared key which can be easily compromised.

C.

Base64 encoding does not encrypt the contents of the Secret, only obfuscates it.

D.

Base64 encoding is not supported by all Secret Stores.

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.