KCSA Compliance And Security Frameworks Practice Question
A compliance officer wants to continuously audit Kubernetes resource manifests for misconfigurations against security best practices before they are applied. Which tool type is best suited for this shift-left compliance approach?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Static code analysis and admission controllers
Policy-as-code engines like OPA Gatekeeper or Kyverno validate and audit Kubernetes manifests prior to admission into the cluster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Log shippers
Why it's wrong here
Log shippers forward log data to centralized storage.
- ✗
Packet analyzers
Why it's wrong here
Packet analyzers inspect network traffic packets.
- ✓
Static code analysis and admission controllers
Why this is correct
Admission controllers enforce policy compliance at deployment time.
- ✗
Kernel debuggers
Why it's wrong here
Kernel debuggers troubleshoot low-level OS kernel execution.
About these practice questions
This KCSA question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official CNCF / Linux Foundation exam blueprint
This KCSA practice question is part of Courseiva's free CNCF / Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCSA exam.