Free KCSA (Kubernetes and Cloud Native Security Associate) practice: the 6 official domains, exam-style questions, a timed practice exam and more.
Play the KCSA map → · Official KCSA exam page
The 4Cs, cloud and infrastructure security, controls, isolation, image and code security
API server, controller manager, scheduler, kubelet, runtime, kube-proxy, etcd, networking, storage
Pod Security Standards and Admission, authn/authz, Secrets, isolation, audit, NetworkPolicy
Trust boundaries, persistence, DoS, compromised containers, network attackers, privilege escalation
Supply chain, image repositories, observability, service mesh, PKI, admission control
Compliance frameworks, threat modelling frameworks, supply chain compliance, tooling
Answer: Several independent layers of controls, so one failure does not expose everything. The 4Cs model is defence in depth: cloud, cluster, container and code each add their own controls.
Answer: Code. Code is the innermost layer: dependencies, secrets in code, input validation.
Answer: A sandboxed runtime such as gVisor or Kata Containers. Namespaces are logical; sandboxed runtimes add a real isolation boundary between container and host kernel.
Answer: Catch issues earlier in development, e.g. scanning in CI. Fixing a vulnerability before it ships is cheaper than after.
Answer: Fewer packages means fewer vulnerabilities and fewer tools for an attacker. No shell or package manager also limits what an attacker can do after a compromise.
Answer: Per-workload cloud identities with least privilege, and blocking the metadata endpoint. Broad node credentials reachable via the metadata service are a classic escalation path.
Answer: A controlled source of trusted, scanned and signed images. Restrict which registries clusters may pull from and scan what is pushed there.
Answer: Run as non-root, drop capabilities, no privilege escalation. Give each workload only what it needs.
Answer: Audit logging with alerts on suspicious API calls. Detective controls notice and report; preventive controls stop the action.
Answer: Anyone who can pull the image can extract them, and rotating means rebuilding. Inject secrets at runtime (Secret objects, external stores) instead.
Answer: Changes go through a reviewed build instead of live edits, so drift and tampering stand out. Replace, don’t patch in place.
Answer: --anonymous-auth=false. Anonymous requests become the system:anonymous user unless disabled.
Answer: Node and RBAC. --authorization-mode=Node,RBAC: the Node authorizer for kubelets, RBAC for everything else.
Answer: Encryption of resources such as Secrets at rest in etcd. An EncryptionConfiguration lists which resources to encrypt and with which provider.
Answer: Mutual TLS between the API server and etcd; Network access restricted to the control plane. Whoever can read etcd can read every Secret.
Answer: 10250. 6443 is the API server, 2379 etcd. The kubelet API on 10250 must require authentication.
Answer: authorization.mode: Webhook (delegated to the API server). Webhook mode asks the API server (SubjectAccessReview) whether the caller may do it.
Answer: Limits a kubelet to modifying its own Node object and Pods bound to it. It contains the blast radius of a compromised node’s credentials.
Answer: Localhost or a protected interface, with authenticated endpoints. Their health/metrics ports should not be openly reachable.
Answer: kube-controller-manager (its CSR signer). --cluster-signing-key-file — protect it like the CA itself.
Answer: allowPrivilegeEscalation: false (no_new_privs). It sets the Linux no_new_privs flag on the container process.
Answer: Restricts which system calls a container may make. RuntimeDefault is a sensible baseline profile from the container runtime.
Answer: It lets the Pod control the runtime and start privileged containers on the node. Access to the runtime socket is effectively root on the node.
Answer: Its metrics and health endpoints should not be exposed beyond the node. kube-proxy runs privileged with host networking; keep its ports internal.
Answer: Short-lived, audience-bound tokens projected by the kubelet via the TokenRequest API. Bound tokens expire and are rotated; legacy auto-created token Secrets are no longer the default.
Answer: Protecting kubeconfig files and their credentials; Short-lived credentials such as OIDC tokens. A kubeconfig is a key to the cluster.
Answer: Restricting hostPath volumes, which expose the node filesystem. hostPath can give a Pod access to sensitive node files; restricted Pod Security disallows it.
Answer: A CNI plugin that enforces NetworkPolicy. Without enforcement, NetworkPolicies are silently ignored.
Answer: It shares the node’s network namespace, bypassing Pod network isolation. It can see and bind node interfaces and reach node-local services.
Answer: enforce; audit; warn. enforce rejects; audit records in the audit log; warn returns a warning to the user.
Answer: Label it, e.g. pod-security.kubernetes.io/enforce=baseline. Pod Security Admission reads namespace labels; PodSecurityPolicy was removed in v1.25.
Answer: runAsNonRoot; Dropping all capabilities; allowPrivilegeEscalation: false. Restricted also requires a seccomp profile (RuntimeDefault or Localhost).
Answer: X.509 client certificates; OIDC tokens. Kubernetes has no User object — identities come from certificates, tokens or an IdP.
Answer: Authentication proves who you are; authorization decides what you may do. The API server authenticates, then authorizes, then runs admission.
Answer: Grants a ClusterRole across the whole cluster. Use a RoleBinding to grant a ClusterRole inside a single namespace instead.
Answer: It lets a user grant permissions they do not have themselves. RBAC normally prevents privilege escalation; these verbs bypass that check.
Answer: Creating Pods in that namespace. A Pod can mount any Secret in its namespace.
Answer: An external secret store via a CSI driver or external secrets operator. Vaults and cloud secret managers can supply secrets at runtime.
Answer: Grant get on specific Secrets by name instead of list/watch on all. list and watch reveal every Secret’s content in the namespace.
Answer: API requests: who made them, what they did, when and the result. Audit policy levels control how much of each request is kept.
Answer: Metadata. Metadata logs user, verb, resource and timestamp.
Answer: All ingress to Pods in that namespace is denied. That is the standard default-deny ingress policy.
Answer: Yes, with a namespaceSelector. from/to entries can combine namespaceSelector and podSelector.
Answer: To scope RBAC, quotas and network policies per tenant. Namespaces are a soft boundary; stronger isolation needs more (nodes, sandboxes, separate clusters).
Answer: The Pod gets no API token unless it needs one. Fewer credentials in Pods means less to steal.
Answer: ResourceQuota. LimitRange sets per-Pod defaults and bounds; ResourceQuota caps the namespace total.
Answer: Spoofing. Spoofing is pretending to be someone else.
Answer: Tampering. Image signing and verification mitigate tampering.
Answer: Repudiation. Audit logging counters repudiation.
Answer: Elevation of privilege. Privileged settings and kernel vulnerabilities enable it.
Answer: Using one compromised workload to reach and attack others. NetworkPolicies, least privilege and mTLS limit it.
Answer: Creating a hidden CronJob or DaemonSet that keeps re-running malicious code. Attackers use workloads, webhooks or static Pods to survive restarts.
Answer: Inject malicious containers into every new Pod. Mutating webhooks can change any object they intercept — protect who can create them.
Answer: Container to host node. The node is the next boundary after the container.
Answer: Anyone who reaches it can run commands in Pods on that node. The kubelet API includes exec and logs endpoints.
Answer: A read-only root filesystem; Dropping all capabilities. Hardening the runtime context restricts what malicious code can do.
Answer: Sending sensitive data out of the cluster — restrict egress with NetworkPolicies. Default-deny egress makes unexpected outbound connections fail and stand out.
Answer: It often holds deploy credentials and can push changed artifacts. Supply chain attacks frequently target the build and deploy pipeline.
Answer: Which of your images contain the affected package. A Software Bill of Materials lists every component in an artifact.
Answer: Levels of supply chain integrity, especially build provenance. SLSA (Supply-chain Levels for Software Artifacts) defines provenance requirements per level.
Answer: Proof of who built it and that it has not changed. Admission policies can then verify signatures before Pods run.
Answer: At admission, before Pods are created. Kyverno, Gatekeeper or an image policy webhook can reject unsigned images.
Answer: Kyverno; OPA Gatekeeper. Both plug into admission via webhooks.
Answer: CEL (Common Expression Language). It avoids running a webhook for many validation needs.
Answer: API server audit logs. exec calls appear as pods/exec requests in the audit log.
Answer: Suspicious behaviour from system calls, e.g. a shell spawned in a container. It alerts on behaviour, not on known signatures.
Answer: Certificates that authenticate and encrypt component communication. kubeadm creates the cluster CA and component certificates.
Answer: Rotate or renew them before they expire. kubeadm certs check-expiration and kubeadm certs renew help; upgrades also renew them.
Answer: Every request is authenticated and authorized per workload identity, not by network location. Identity-based mTLS plus authorization policies.
Answer: Blocking images with critical vulnerabilities from being deployed. Scan results can feed admission or pipeline gates.
Answer: Consensus-based secure configuration recommendations for Kubernetes. kube-bench checks a cluster against it.
Answer: kube-bench. kube-bench reports PASS/FAIL/WARN per recommendation.
Answer: Systematically identifying what could go wrong and prioritizing mitigations. Frameworks like STRIDE give it structure.
Answer: Real-world attacker tactics and techniques. It includes a matrix for containers.
Answer: NIST’s Application Container Security Guide. It covers risks and countermeasures for images, registries, orchestrators, containers and hosts.
Answer: Proving where artifacts came from and what is inside them (provenance, SBOMs). Regulations increasingly require SBOMs and provenance.
Answer: Continuous, repeatable evidence instead of occasional manual audits. Policy-as-code and scanners produce evidence on every change.
Answer: A standard severity score for vulnerabilities. Scanners report CVSS scores to help prioritize fixes.
Answer: Cloud. Cloud → Cluster → Container → Code. Each inner layer depends on the security of the ones around it.
Answer: RBAC for your users and workloads; The security of the container images you deploy. The provider secures what it operates; everything you configure and deploy remains yours.
Answer: etcd. Secrets are stored in etcd. Protect it with mTLS, network isolation and encryption at rest.
Answer: NodeRestriction. Combined with the Node authorizer, NodeRestriction stops a compromised kubelet from tampering with other nodes.
Answer: restricted. privileged (no restrictions) → baseline (blocks known escalations) → restricted (current hardening best practice).
Answer: Its data is only base64-encoded, so anyone who can read it can decode it. Encode ≠ encrypt. Restrict access with RBAC and enable encryption at rest or use an external secret store.
Answer: Anything not explicitly granted by some binding is denied. RBAC permissions are purely additive on top of a default deny.
Answer: privileged: true; A hostPath mount of /. Privileged mode and mounting the host filesystem hand the container the node. The other settings reduce risk.
Answer: Denial of service — ResourceQuotas and limits per namespace. Resource exhaustion is DoS; quotas and limits bound what one tenant can consume.
Answer: Admission control (an admission webhook). Admission runs after authn/authz and before the object is stored, which is where Kyverno or Gatekeeper act (Kyverno verifies images in its admission webhooks and can pin them to digests).
Answer: Mutual TLS with workload identities. Sidecars or node proxies authenticate both sides and encrypt the traffic between them.
Answer: STRIDE. STRIDE categorizes threats; CIS and PSS prescribe configuration, kube-bench checks against CIS.