KCSA Overview OF Cloud Native Security Practice Question
According to the shared responsibility model for a cloud-managed Kubernetes service, who is responsible for managing application data encryption keys (using KMS) and application-level secrets?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The customer
Application secrets and encryption keys managed via KMS for application payloads are the customer's responsibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The cloud provider
Why it's wrong here
Cloud providers do not manage application secrets or customer business data.
- ✓
The customer
Why this is correct
Customers are responsible for application security, data classification, and secrets management.
- ✗
The Linux Foundation
Why it's wrong here
The Linux Foundation hosts open-source projects; they do not manage enterprise keys.
- ✗
The container runtime vendor
Why it's wrong here
Runtime vendors (like containerd) do not manage cloud KMS keys.
About these practice questions
One of 320 original KCSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official CNCF / Linux Foundation exam blueprint
This KCSA practice question is part of Courseiva's free CNCF / Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCSA exam.