Courseiva
KCSA
Kubernetes Security FundamentalsmediumMultiple SelectObjective-mapped

KCSA Kubernetes Security Fundamentals Practice Question

Which TWO of the following statements are true regarding Kubernetes Secrets and their security posture by default?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Mounting a Secret as an environment variable can expose the secret value in container logs or crash dumps.

Kubernetes Secrets are base64 encoded (not encrypted) by default in etcd, and access to them can be controlled via RBAC.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Mounting a Secret as an environment variable can expose the secret value in container logs or crash dumps.

    Why this is correct

    Environment variables are visible via process listings and diagnostic dumps, making volume mounts generally more secure for secrets.

  • Secrets are strongly encrypted at rest using AES-256 encryption by default in etcd.

    Why it's wrong here

    By default, secrets are only base64 encoded in etcd, not encrypted at rest unless an encryption configuration is explicitly enabled.

  • RBAC can be used to restrict which users and ServiceAccounts can read Secrets within a namespace.

    Why this is correct

    RBAC rules can target Secrets specifically (e.g., verbs get, list, watch on resource secrets).

  • Secrets automatically expire and rotate every 30 days unless explicitly disabled.

    Why it's wrong here

    Kubernetes Secrets do not have a built-in automatic expiration or rotation mechanism without external tools.

  • Secrets encoded in base64 provide cryptographic security comparable to robust symmetric encryption.

    Why it's wrong here

    Base64 is an encoding scheme, not encryption; anyone with access to the object can decode it instantly.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This KCSA question is part of Courseiva's 320-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official CNCF / Linux Foundation exam blueprint

This KCSA practice question is part of Courseiva's free CNCF / Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCSA exam.