KCSA Overview OF Cloud Native Security Practice Question
An administrator is designing a security posture for a microservices application deployed in a Kubernetes cluster. According to the 4Cs of Cloud Native Security, which component falls under the 'Code' layer?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application dependency libraries in package.json
The Code layer encompasses application source code, third-party libraries, and software dependencies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Container base images like Alpine Linux
Why it's wrong here
Base images are part of the Container layer.
- ✓
Application dependency libraries in package.json
Why this is correct
Application dependencies and source code belong to the Code layer.
- ✗
Kubernetes API server authorization policies
Why it's wrong here
API server authorization is part of the Cluster layer.
- ✗
Cloud provider IAM roles
Why it's wrong here
IAM roles belong to the Cloud layer.
About these practice questions
This KCSA question is part of Courseiva's 320-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official CNCF / Linux Foundation exam blueprint
This KCSA practice question is part of Courseiva's free CNCF / Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCSA exam.