KCSA · domain
Compliance And Security Frameworks
Practise RAM questions covering identification, installation, speeds, dual-channel, and troubleshooting for the KCSA exam.
Focused practice
Practice Compliance And Security Frameworks questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Compliance And Security Frameworks
RAM tests your ability to identify, install, and troubleshoot memory types, speeds, and configurations for PCs.
Identifying DDR3 vs DDR4 vs DDR5 physical and electrical differences
Matching RAM speed (MHz) to motherboard and CPU support
Calculating total memory capacity from module size and slots
Troubleshooting common RAM errors like beep codes and blue screens
Why learners struggle
Why Compliance And Security Frameworks questions are commonly missed
RAM questions are commonly missed because learners confuse physical form factors (DIMM vs SO-DIMM) and fail to distinguish between memory speed (MHz) and latency (CL).
- ·DIMM vs SO-DIMM — desktop vs laptop form factor confusion
- ·DDR3 vs DDR4 vs DDR5 — notch position and voltage differences
- ·MHz vs CL — speed vs latency trade-offs in performance
- ·Single-channel vs dual-channel — bandwidth impact misconception
- ·ECC vs non-ECC — error correction support in servers vs desktops
- ·32-bit vs 64-bit — maximum addressable RAM limit
Watch out for
Common Compliance And Security Frameworks exam traps
- ▸Confusing DDR3 and DDR4 notch positions and voltage requirements
- ▸Assuming dual-channel requires identical size modules only
- ▸Mixing ECC and non-ECC RAM in a single system
- ▸Forgetting that 32-bit OS limits usable RAM to 4 GB
Question index
All Compliance And Security Frameworks questions (29)
Click any question to see the full explanation, or start a practice session above.
A compliance officer wants to continuously audit Kubernetes resource manifests for misconfigurations against security best practices before they are applied. Which tool type is best suited for this shift-left compliance approach?
Easy2An auditor is assessing compliance with NIST SP 800-53 controls for access control (AC) within a managed Kubernetes cluster. Which API object enforces fine-grained authorization decisions directly at the Kubernetes API server?
Hard3An enterprise undergoes an ISO/IEC 27001 audit for their Kubernetes environment. The auditor requests evidence that secrets at rest are encrypted. Which configuration component enables encryption of Secret resources in etcd?
Hard4According to the CIS Kubernetes Benchmark, anonymous requests to the Kubernetes API server should be disabled. Which kube-apiserver flag enforces this setting?
Medium5An enterprise is adopting the Cloud Native Security Framework to map their controls. Which of the 4Cs of Cloud Native Security represents the outermost layer encompassing physical data centers and hardware?
Easy6When evaluating a Kubernetes cluster against security and compliance baselines, which TWO tools are commonly used for automated auditing and benchmarking? (Choose TWO)
Easy7A security analyst wants to scan container images for known Common Vulnerabilities and Exposures (CVEs) as part of a continuous compliance pipeline. Which tool is widely used for this purpose?
Easy8To comply with CIS benchmarks regarding pod security, an administrator wants to prevent containers from running with root privileges. Which field in a Pod Security Standard (restricted profile) enforces this?
Medium9A security engineer is configuring kube-apiserver audit logging to satisfy NIST compliance requirements. Which configuration file specifies which requests are logged and at what log level?
Hard10An auditor is inspecting a Kubernetes cluster for compliance with the CIS Benchmark for etcd security. Which THREE configurations must be verified for the etcd cluster? (Choose THREE)
Hard11Which CNCF project acts as a cloud-native runtime security and intrusion detection tool that monitors system calls against predefined security rules?
Easy12An auditor notices that kubelet authentication is set to always allow anonymous access in a cluster configuration. According to the CIS Benchmark, what should the kubelet configuration parameter "authentication.anonymous.enabled" be set to?
Medium13Which TWO actions are core tenets of the "Shift-Left" security philosophy in cloud-native compliance? (Choose TWO)
Easy14A compliance team is adopting the NIST SP 800-190 standard to secure their container image pipeline. Which THREE practices are recommended in this framework for managing container images? (Choose THREE)
Medium15An administrator needs to evaluate an existing Kubernetes cluster against the CIS Kubernetes Benchmark. Which tool provides automated scanning specifically tailored to this benchmark?
Easy16A security architect is designing role-based access control (RBAC) to comply with NIST access control principles of least privilege. Which THREE best practices should be followed when creating Roles and ClusterRoles? (Choose THREE)
Medium17An auditor is reviewing compliance with CIS Kubernetes Benchmark control 1.2.20, which relates to the kube-apiserver admission control configuration. Which admission plugin is recommended by CIS to prevent default service accounts from automatically mounting API credentials?
Hard18Which NIST framework publication specifically addresses the security of container-based applications and orchestration systems?
Easy19Under NIST guidelines for continuous monitoring in cloud-native environments, which Kubernetes mechanism allows operators to enforce cryptographic integrity of container images at runtime?
Medium20An organization requires compliance auditing of etcd access to ensure unauthorized clients cannot communicate with the data store. According to CIS benchmarks, how should etcd client communication be secured?
Hard21A security engineer is reviewing the NIST SP 800-190 container security application and needs to identify the primary control category for securing container image registries. Under NIST guidelines, which layer is primarily responsible for verifying the integrity of images before deployment?
Medium22A security engineer needs to verify that control plane component pods (such as kube-apiserver and etcd) have correct file ownership on the control plane node. According to CIS benchmarks, who should own these manifest files located in "/etc/kubernetes/manifests"?
Medium23A security team is implementing Pod Security Standards (restricted, baseline, privileged) across namespaces. Which THREE controls are enforced under the Restricted Pod Security profile? (Choose THREE)
Medium24A security team is implementing NIST SP 800-190 guidelines for container runtime security. Which kernel feature is leveraged by container runtimes to restrict system calls and meet least-privilege execution requirements?
Hard25Which open-source auditing tool provides compliance scores and checks against Kubernetes security frameworks such as NSA-CISA and CIS?
Easy26An enterprise is enforcing the CIS Kubernetes Benchmark for control plane configuration. Which TWO parameters must be correctly configured on the kube-apiserver to meet strict compliance auditing standards? (Choose TWO)
Hard27An auditor reviews container runtime configurations for compliance with NIST SP 800-190 recommendations on privilege escalation. Which Kubernetes feature controls whether a process can gain more privileges than its parent process?
Hard28An enterprise security auditor is reviewing Kubernetes API server admission control configurations for compliance. Which THREE admission plugins or mechanisms are critical for enforcing security policies at admission time? (Choose THREE)
Hard29A security team needs to ensure that Kubernetes nodes have secure file permissions for the kubelet configuration files, in alignment with CIS benchmarks. What should the file permissions on "/etc/kubernetes/kubelet.conf" typically be set to?
MediumOther domains
All KCSA exam domains
Frequently asked questions
- What does the Compliance And Security Frameworks domain cover on the KCSA exam?
- RAM tests your ability to identify, install, and troubleshoot memory types, speeds, and configurations for PCs.
- How many questions are in this domain?
- This page lists all 29 Compliance And Security Frameworks questions in the KCSA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Compliance And Security Frameworks questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.