Courseiva
Back to Kubernetes and Cloud Native Security Associate (KCSA, CNCF) (KCSA) questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Kubernetes and Cloud Native Security Associate (KCSA, CNCF) (KCSA) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
KCSA
exam code
CNCF / Linux Foundation
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related KCSA topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

An enterprise security auditor is reviewing Kubernetes API server admission control configurations for compliance. Which THREE admission plugins or mechanisms are critical for enforcing security policies at admission time? (Choose THREE)

Question 2easymulti select
Full question →

When evaluating a Kubernetes cluster against security and compliance baselines, which TWO tools are commonly used for automated auditing and benchmarking? (Choose TWO)

Question 3hardmulti select
Full question →

An enterprise is enforcing the CIS Kubernetes Benchmark for control plane configuration. Which TWO parameters must be correctly configured on the kube-apiserver to meet strict compliance auditing standards? (Choose TWO)

Question 4hardmulti select
Full question →

Which TWO of the following kubelet security configurations are critical for preventing container escape and unauthorized node API access? (Choose TWO)

Question 5mediummulti select
Full question →

Which THREE of the following practices should be followed when configuring Kubernetes audit logging? (Choose THREE)

Question 6easymulti select
Full question →

Which TWO of the following are valid Kubernetes RBAC rule subjects that can be bound to roles or cluster roles?

Question 7easymulti select
Full question →

Which TWO actions are core tenets of the "Shift-Left" security philosophy in cloud-native compliance? (Choose TWO)

Question 8easymulti select
Full question →

Which TWO of the following actions are risks associated with leaving the Kubernetes API server's insecure port enabled? (Choose TWO)

Question 9hardmulti select
Full question →

An auditor is inspecting a Kubernetes cluster for compliance with the CIS Benchmark for etcd security. Which THREE configurations must be verified for the etcd cluster? (Choose THREE)

Question 10mediummulti select
Full question →

A security architect is designing role-based access control (RBAC) to comply with NIST access control principles of least privilege. Which THREE best practices should be followed when creating Roles and ClusterRoles? (Choose THREE)

Question 11hardmulti select
Full question →

When configuring Pod Security Standards on a namespace, which THREE security restrictions are enforced by the 'restricted' profile that are NOT enforced by the 'baseline' profile? (Choose THREE)

Question 12mediummulti select
Full question →

Which TWO of the following statements are true regarding Kubernetes Secrets and their security posture by default?

Question 13mediummulti select
Full question →

Which TWO of the following methods can be used to authenticate users or systems against the Kubernetes API server? (Choose TWO)

Question 14easymulti select
Full question →

Which TWO of the following are core security hardening best practices for the Kubernetes API server? (Choose TWO)

Question 15mediummulti select
Full question →

A security team is implementing Pod Security Standards (restricted, baseline, privileged) across namespaces. Which THREE controls are enforced under the Restricted Pod Security profile? (Choose THREE)

Question 16mediummulti select
Full question →

A compliance team is adopting the NIST SP 800-190 standard to secure their container image pipeline. Which THREE practices are recommended in this framework for managing container images? (Choose THREE)

Question 17easymulti select
Full question →

Which THREE methods can be used to inject Kubernetes Secrets into a running pod?

Question 18easymulti select
Full question →

Which TWO entities can be assigned RBAC permissions in a Kubernetes cluster? (Choose TWO)

Question 19easymulti select
Full question →

Which THREE of the following are key components of the Kubernetes control plane? (Choose THREE)

Question 20hardmulti select
Full question →

Which TWO of the following API server configuration flags help enforce cryptographic and transport security? (Choose TWO)

These KCSA practice questions are part of Courseiva's free CNCF / Linux Foundation certification practice question bank. Courseiva provides original exam-style KCSA questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.