Practice KCSA Compliance And Security Frameworks questions with full explanations on every answer.
Start practicing
Compliance And Security Frameworks — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An auditor is assessing compliance with NIST SP 800-53 controls for access control (AC) within a managed Kubernetes cluster. Which API object enforces fine-grained authorization decisions directly at the Kubernetes API server?
2An enterprise is adopting the Cloud Native Security Framework to map their controls. Which of the 4Cs of Cloud Native Security represents the outermost layer encompassing physical data centers and hardware?
3According to the CIS Kubernetes Benchmark, anonymous requests to the Kubernetes API server should be disabled. Which kube-apiserver flag enforces this setting?
4A compliance officer wants to continuously audit Kubernetes resource manifests for misconfigurations against security best practices before they are applied. Which tool type is best suited for this shift-left compliance approach?
5A security team is implementing NIST SP 800-190 guidelines for container runtime security. Which kernel feature is leveraged by container runtimes to restrict system calls and meet least-privilege execution requirements?
6A security engineer is reviewing the NIST SP 800-190 container security application and needs to identify the primary control category for securing container image registries. Under NIST guidelines, which layer is primarily responsible for verifying the integrity of images before deployment?
7An auditor notices that kubelet authentication is set to always allow anonymous access in a cluster configuration. According to the CIS Benchmark, what should the kubelet configuration parameter "authentication.anonymous.enabled" be set to?
8An administrator needs to evaluate an existing Kubernetes cluster against the CIS Kubernetes Benchmark. Which tool provides automated scanning specifically tailored to this benchmark?
9Which CNCF project acts as a cloud-native runtime security and intrusion detection tool that monitors system calls against predefined security rules?
10To comply with CIS benchmarks regarding pod security, an administrator wants to prevent containers from running with root privileges. Which field in a Pod Security Standard (restricted profile) enforces this?
11A security engineer is configuring kube-apiserver audit logging to satisfy NIST compliance requirements. Which configuration file specifies which requests are logged and at what log level?
12An enterprise undergoes an ISO/IEC 27001 audit for their Kubernetes environment. The auditor requests evidence that secrets at rest are encrypted. Which configuration component enables encryption of Secret resources in etcd?
13Which NIST framework publication specifically addresses the security of container-based applications and orchestration systems?
14An auditor is reviewing compliance with CIS Kubernetes Benchmark control 1.2.20, which relates to the kube-apiserver admission control configuration. Which admission plugin is recommended by CIS to prevent default service accounts from automatically mounting API credentials?
15A security team needs to ensure that Kubernetes nodes have secure file permissions for the kubelet configuration files, in alignment with CIS benchmarks. What should the file permissions on "/etc/kubernetes/kubelet.conf" typically be set to?
16A security analyst wants to scan container images for known Common Vulnerabilities and Exposures (CVEs) as part of a continuous compliance pipeline. Which tool is widely used for this purpose?
17Under NIST guidelines for continuous monitoring in cloud-native environments, which Kubernetes mechanism allows operators to enforce cryptographic integrity of container images at runtime?
18An organization requires compliance auditing of etcd access to ensure unauthorized clients cannot communicate with the data store. According to CIS benchmarks, how should etcd client communication be secured?
19Which open-source auditing tool provides compliance scores and checks against Kubernetes security frameworks such as NSA-CISA and CIS?
20A security engineer needs to verify that control plane component pods (such as kube-apiserver and etcd) have correct file ownership on the control plane node. According to CIS benchmarks, who should own these manifest files located in "/etc/kubernetes/manifests"?
21An auditor reviews container runtime configurations for compliance with NIST SP 800-190 recommendations on privilege escalation. Which Kubernetes feature controls whether a process can gain more privileges than its parent process?
22A compliance team is adopting the NIST SP 800-190 standard to secure their container image pipeline. Which THREE practices are recommended in this framework for managing container images? (Choose THREE)
23An enterprise is enforcing the CIS Kubernetes Benchmark for control plane configuration. Which TWO parameters must be correctly configured on the kube-apiserver to meet strict compliance auditing standards? (Choose TWO)
24When evaluating a Kubernetes cluster against security and compliance baselines, which TWO tools are commonly used for automated auditing and benchmarking? (Choose TWO)
25An auditor is inspecting a Kubernetes cluster for compliance with the CIS Benchmark for etcd security. Which THREE configurations must be verified for the etcd cluster? (Choose THREE)
26A security architect is designing role-based access control (RBAC) to comply with NIST access control principles of least privilege. Which THREE best practices should be followed when creating Roles and ClusterRoles? (Choose THREE)
27Which TWO actions are core tenets of the "Shift-Left" security philosophy in cloud-native compliance? (Choose TWO)
28An enterprise security auditor is reviewing Kubernetes API server admission control configurations for compliance. Which THREE admission plugins or mechanisms are critical for enforcing security policies at admission time? (Choose THREE)
29A security team is implementing Pod Security Standards (restricted, baseline, privileged) across namespaces. Which THREE controls are enforced under the Restricted Pod Security profile? (Choose THREE)
The Compliance And Security Frameworks domain covers the key concepts tested in this area of the KCSA exam blueprint published by CNCF / Linux Foundation. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all KCSA domains — no account required.
The Courseiva KCSA question bank contains 29 questions in the Compliance And Security Frameworks domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Compliance And Security Frameworks domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included