KCSA Kubernetes Cluster Component Security Practice Question
Which TWO of the following actions are risks associated with leaving the Kubernetes API server's insecure port enabled? (Choose TWO)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Complete bypass of all authentication mechanisms.
The insecure port allows unauthenticated and unencrypted access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enforcement of strict TLS 1.3 encryption on all connections.
Why it's wrong here
The insecure port uses plaintext HTTP, not TLS.
- ✓
Complete bypass of all authentication mechanisms.
Why this is correct
The insecure port does not require authentication.
- ✗
Mandatory mutual TLS client certificate verification.
Why it's wrong here
It does not require client certificates.
- ✗
Automatic activation of etcd encryption at rest.
Why it's wrong here
It has no effect on etcd data encryption.
- ✓
Complete bypass of all authorization checks (RBAC).
Why this is correct
Requests sent to the insecure port do not undergo authorization.
About these practice questions
Courseiva writes every KCSA question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official CNCF / Linux Foundation exam blueprint
This KCSA practice question is part of Courseiva's free CNCF / Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCSA exam.