KCSA Kubernetes Security Fundamentals Practice Question
Which TWO of the following statements are true regarding Kubernetes Secrets and their security posture by default?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mounting a Secret as an environment variable can expose the secret value in container logs or crash dumps.
Kubernetes Secrets are base64 encoded (not encrypted) by default in etcd, and access to them can be controlled via RBAC.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Mounting a Secret as an environment variable can expose the secret value in container logs or crash dumps.
Why this is correct
Environment variables are visible via process listings and diagnostic dumps, making volume mounts generally more secure for secrets.
- ✗
Secrets are strongly encrypted at rest using AES-256 encryption by default in etcd.
Why it's wrong here
By default, secrets are only base64 encoded in etcd, not encrypted at rest unless an encryption configuration is explicitly enabled.
- ✓
RBAC can be used to restrict which users and ServiceAccounts can read Secrets within a namespace.
Why this is correct
RBAC rules can target Secrets specifically (e.g., verbs get, list, watch on resource secrets).
- ✗
Secrets automatically expire and rotate every 30 days unless explicitly disabled.
Why it's wrong here
Kubernetes Secrets do not have a built-in automatic expiration or rotation mechanism without external tools.
- ✗
Secrets encoded in base64 provide cryptographic security comparable to robust symmetric encryption.
Why it's wrong here
Base64 is an encoding scheme, not encryption; anyone with access to the object can decode it instantly.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
This KCSA question is part of Courseiva's 320-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official CNCF / Linux Foundation exam blueprint
This KCSA practice question is part of Courseiva's free CNCF / Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCSA exam.