Courseiva

KCSA · topic practice

Kubernetes Cluster Component Security practice questions

Practise Kubernetes and Cloud Native Security Associate (KCSA, CNCF) (KCSA) Kubernetes Cluster Component Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Kubernetes Cluster Component Security

What the exam tests

What to know about Kubernetes Cluster Component Security

Kubernetes Cluster Component Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Kubernetes Cluster Component Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Kubernetes Cluster Component Security questions

20 questions · select your answer, then reveal the explanation

An administrator wants to ensure that API requests containing deprecated API versions trigger warnings in client output and audit logs. Which API server flag controls this behavior?

Which component acts as the local agent running on every Kubernetes worker node, responsible for maintaining pod lifecycles and container health?

Which TWO of the following are primary benefits of enabling encryption at rest for Kubernetes secrets? (Choose THREE - wait, choose TWO)

You are hardening a production Kubernetes control plane. You need to ensure that etcd client-to-server and peer communications are strictly encrypted in transit and require mutual TLS (mTLS). Which etcd configuration flag combination enforces this requirement?

A security scan reveals that the kubelet read-only port (typically port 1055) is active and exposes unauthenticated pod and cluster metadata. How should this vulnerability be remediated?

When configuring the Kubernetes API server authorization modes, which mode evaluates requests against Kubernetes RBAC policies?

You are auditing the Kubernetes control plane and notice that the API server is configured with an insecure port (--insecure-port=8080). What is the primary security implication of leaving this port enabled?

A security auditor discovers that anonymous authentication is accidentally enabled on the Kubernetes API server, allowing unauthenticated read access to cluster health endpoints. Which API server flag must be modified to disable anonymous requests?

An administrator needs to restrict kubelets so they can only modify resources associated with their own node (such as their own Node object and Pods bound to them). Which authorization mode must be enabled alongside RBAC?

An engineer needs to verify that the kubelet on worker nodes is not allowing unauthenticated requests. Which configuration parameter in the kubelet configuration file disables anonymous access?

An administrator needs to secure access to the Kubernetes API server from an external CI/CD pipeline. Which mechanism should be used to authenticate the pipeline using an existing external identity provider without embedding long-lived static tokens?

Which component in the Kubernetes control plane is directly responsible for interacting with etcd to persist and retrieve cluster state?

An administrator wants to prevent the kubelet from automatically approving certificate signing requests (CSRs) generated by nodes joining the cluster. Which mechanism manages kubelet TLS bootstrapping approval behavior?

You are hardening etcd and want to ensure that sensitive data stored in Kubernetes secrets is encrypted at rest within etcd. Which API server configuration file parameter specifies how secrets should be encrypted?

An incident response team suspects that an attacker has gained unauthorized access to the cluster via an unencrypted etcd backup file containing sensitive cluster state. Which etcd utility should be used to securely snapshot and backup etcd data?

Where are static pods for a control plane node typically defined so that the kubelet can automatically create and manage them?

A cluster administrator wants to implement admission control auditing to record all mutating and validating requests made to the API server. Which component configuration handles this requirement?

You are reviewing security logs on a control plane node and discover that an unauthenticated user accessed the kubelet's HTTPS port (10250) to execute commands inside containers. How should you restrict kubelet authentication and authorization to prevent this?

Which file on a Kubernetes control plane node contains the startup arguments and flags for the statically hosted API server?

You need to audit the cryptographic algorithms and TLS versions permitted by the Kubernetes API server for incoming client connections. Which API server flag enforces a minimum TLS version of 1.3?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Kubernetes Cluster Component Security sessions

Start a Kubernetes Cluster Component Security only practice session

Every question in these sessions is drawn from the Kubernetes Cluster Component Security domain — nothing else.

Related practice questions

Related KCSA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the KCSA exam test about Kubernetes Cluster Component Security?
Kubernetes Cluster Component Security questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Kubernetes Cluster Component Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Kubernetes Cluster Component Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other KCSA topics?
Use the topic links above to move to related areas, or go back to the KCSA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the KCSA exam covers. They are not copied from any real exam or dump site.