CGOA Tooling Practice Question
Which THREE of the following are essential tasks when implementing SOPS with GitOps?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configuring the KMS or local key (e.g., Age)
You must create the encryption key, integrate with the GitOps tool (Flux/Argo), and ensure the key is available to the controller as a Secret.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enabling Git LFS for encrypted files
Why it's wrong here
Not required for SOPS.
- ✗
Running a custom CI/CD build to decrypt
Why it's wrong here
GitOps should be the decryptor.
- ✓
Configuring the KMS or local key (e.g., Age)
Why this is correct
Required for encryption/decryption.
- ✓
Storing the private key in the cluster as a secret
Why this is correct
Required for the controller to decrypt.
- ✓
Creating a .sops.yaml config file
Why this is correct
Defines encryption rules.
About these practice questions
One of 325 original CGOA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official CNCF / Linux Foundation exam blueprint
This CGOA practice question is part of Courseiva's free CNCF / Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CGOA exam.