Courseiva
Back to Kubernetes and Cloud Native Security Associate (KCSA, CNCF) (KCSA) questions

Scenario-based practice

Hard Difficulty Questions

Practise Kubernetes and Cloud Native Security Associate (KCSA, CNCF) (KCSA) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
KCSA
exam code
CNCF / Linux Foundation
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related KCSA topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

An enterprise security auditor is reviewing Kubernetes API server admission control configurations for compliance. Which THREE admission plugins or mechanisms are critical for enforcing security policies at admission time? (Choose THREE)

Question 2hardmultiple choice
Full question →

A cluster administrator wants to implement admission control auditing to record all mutating and validating requests made to the API server. Which component configuration handles this requirement?

Question 3hardmulti select
Full question →

An enterprise is enforcing the CIS Kubernetes Benchmark for control plane configuration. Which TWO parameters must be correctly configured on the kube-apiserver to meet strict compliance auditing standards? (Choose TWO)

Question 4hardmulti select
Full question →

Which TWO of the following kubelet security configurations are critical for preventing container escape and unauthorized node API access? (Choose TWO)

Question 5hardmultiple choice
Full question →

An auditor is reviewing compliance with CIS Kubernetes Benchmark control 1.2.20, which relates to the kube-apiserver admission control configuration. Which admission plugin is recommended by CIS to prevent default service accounts from automatically mounting API credentials?

Question 6hardmulti select
Full question →

An auditor is inspecting a Kubernetes cluster for compliance with the CIS Benchmark for etcd security. Which THREE configurations must be verified for the etcd cluster? (Choose THREE)

Question 7hardmultiple choice
Full question →

You are tasked with securing a Kubernetes cluster where control plane nodes are hosted in a private network segment. To prevent unauthorized access to the API server from compromised internal workloads, which mechanism restricts which service accounts can access the API server?

Question 8hardmultiple choice
Full question →

You are reviewing security logs on a control plane node and discover that an unauthenticated user accessed the kubelet's HTTPS port (10250) to execute commands inside containers. How should you restrict kubelet authentication and authorization to prevent this?

Question 9hardmultiple choice
Full question →

You are performing a security review of etcd cluster membership. You need to list all active members of the etcd cluster and check their health status using the command line. Which etcdctl command is correct?

Question 10hardmulti select
Full question →

When configuring Pod Security Standards on a namespace, which THREE security restrictions are enforced by the 'restricted' profile that are NOT enforced by the 'baseline' profile? (Choose THREE)

Question 11hardmultiple choice
Full question →

An auditor reviews container runtime configurations for compliance with NIST SP 800-190 recommendations on privilege escalation. Which Kubernetes feature controls whether a process can gain more privileges than its parent process?

Question 12hardmultiple choice
Full question →

You are hardening etcd on a dedicated control plane host. You want to ensure that etcd database files on disk are protected against unauthorized physical or filesystem access. Which control mechanism is best suited for this?

Question 13hardmultiple choice
Full question →

An organization requires compliance auditing of etcd access to ensure unauthorized clients cannot communicate with the data store. According to CIS benchmarks, how should etcd client communication be secured?

Question 14hardmulti select
Full question →

Which TWO of the following API server configuration flags help enforce cryptographic and transport security? (Choose TWO)

Question 15hardmultiple choice
Full question →

You are reviewing admission webhook configurations and notice that timeoutSeconds is set to 3 seconds for a critical validation webhook. If the webhook server takes 4 seconds to respond, what does the API server do when failurePolicy is 'Ignore'?

Question 16hardmultiple choice
Full question →

An application pod requires access to the Kubernetes API to list other pods. To follow secure practices, you create a dedicated ServiceAccount and bind a custom Role to it. How should you configure the Pod specification to prevent the default service account token from being automatically mounted?

Question 17hardmulti select
Full question →

Which THREE components are involved when an external client authenticates to the Kubernetes API server using OpenID Connect (OIDC)? (Choose THREE)

Question 18hardmulti select
Full question →

Which TWO statements are true regarding Kubernetes NetworkPolicy default behaviors?

Question 19hardmulti select
Full question →

Which TWO of the following mechanisms help secure the kubelet API from unauthorized access and container inspection? (Choose TWO)

Question 20hardmulti select
Full question →

Which TWO of the following scenarios represent severe security misconfigurations in a Kubernetes cluster control plane? (Choose TWO)

These KCSA practice questions are part of Courseiva's free CNCF / Linux Foundation certification practice question bank. Courseiva provides original exam-style KCSA questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.