KubeRusted
Spinning up your cluster…

KCSA exam prep — Kubernetes and Cloud Native Security Associate

Free KCSA (Kubernetes and Cloud Native Security Associate) practice: the 6 official domains, exam-style questions, a timed practice exam and more.

Play the KCSA map → · Official KCSA exam page

Overview of Cloud Native Security (14%)

The 4Cs, cloud and infrastructure security, controls, isolation, image and code security

Kubernetes Cluster Component Security (22%)

API server, controller manager, scheduler, kubelet, runtime, kube-proxy, etcd, networking, storage

Kubernetes Security Fundamentals (22%)

Pod Security Standards and Admission, authn/authz, Secrets, isolation, audit, NetworkPolicy

Kubernetes Threat Model (16%)

Trust boundaries, persistence, DoS, compromised containers, network attackers, privilege escalation

Platform Security (16%)

Supply chain, image repositories, observability, service mesh, PKI, admission control

Compliance and Security Frameworks (10%)

Compliance frameworks, threat modelling frameworks, supply chain compliance, tooling

Practice questions

What is "defence in depth"?

Answer: Several independent layers of controls, so one failure does not expose everything. The 4Cs model is defence in depth: cloud, cluster, container and code each add their own controls.

Which layer of the 4Cs covers vulnerable libraries in your application?

Answer: Code. Code is the innermost layer: dependencies, secrets in code, input validation.

Which isolation technique gives untrusted workloads their own kernel boundary?

Answer: A sandboxed runtime such as gVisor or Kata Containers. Namespaces are logical; sandboxed runtimes add a real isolation boundary between container and host kernel.

What does "shift left" mean in security?

Answer: Catch issues earlier in development, e.g. scanning in CI. Fixing a vulnerability before it ships is cheaper than after.

Why prefer minimal base images such as distroless?

Answer: Fewer packages means fewer vulnerabilities and fewer tools for an attacker. No shell or package manager also limits what an attacker can do after a compromise.

Which control best protects cloud credentials from a compromised Pod?

Answer: Per-workload cloud identities with least privilege, and blocking the metadata endpoint. Broad node credentials reachable via the metadata service are a classic escalation path.

What is a container image registry’s role in security?

Answer: A controlled source of trusted, scanned and signed images. Restrict which registries clusters may pull from and scan what is pushed there.

What is the principle of least privilege applied to a container?

Answer: Run as non-root, drop capabilities, no privilege escalation. Give each workload only what it needs.

Which is a detective control rather than a preventive one?

Answer: Audit logging with alerts on suspicious API calls. Detective controls notice and report; preventive controls stop the action.

Why should Secrets not be baked into container images?

Answer: Anyone who can pull the image can extract them, and rotating means rebuilding. Inject secrets at runtime (Secret objects, external stores) instead.

What does immutable infrastructure improve for security?

Answer: Changes go through a reviewed build instead of live edits, so drift and tampering stand out. Replace, don’t patch in place.

Which kube-apiserver flag disables unauthenticated requests?

Answer: --anonymous-auth=false. Anonymous requests become the system:anonymous user unless disabled.

Which authorization modes are typical for a hardened API server?

Answer: Node and RBAC. --authorization-mode=Node,RBAC: the Node authorizer for kubelets, RBAC for everything else.

What does the API server’s --encryption-provider-config enable?

Answer: Encryption of resources such as Secrets at rest in etcd. An EncryptionConfiguration lists which resources to encrypt and with which provider.

How should etcd be protected?

Answer: Mutual TLS between the API server and etcd; Network access restricted to the control plane. Whoever can read etcd can read every Secret.

Which port does the kubelet API listen on by default?

Answer: 10250. 6443 is the API server, 2379 etcd. The kubelet API on 10250 must require authentication.

How should the kubelet authorize API requests made to it?

Answer: authorization.mode: Webhook (delegated to the API server). Webhook mode asks the API server (SubjectAccessReview) whether the caller may do it.

What does the NodeRestriction admission plugin do?

Answer: Limits a kubelet to modifying its own Node object and Pods bound to it. It contains the blast radius of a compromised node’s credentials.

What should the scheduler and controller manager bind to?

Answer: Localhost or a protected interface, with authenticated endpoints. Their health/metrics ports should not be openly reachable.

Which component runs with the cluster CA key to sign certificate requests?

Answer: kube-controller-manager (its CSR signer). --cluster-signing-key-file — protect it like the CA itself.

What container runtime setting helps prevent a container process from gaining privileges via setuid binaries?

Answer: allowPrivilegeEscalation: false (no_new_privs). It sets the Linux no_new_privs flag on the container process.

What does a seccomp profile do?

Answer: Restricts which system calls a container may make. RuntimeDefault is a sensible baseline profile from the container runtime.

Why is mounting the container runtime socket into a Pod dangerous?

Answer: It lets the Pod control the runtime and start privileged containers on the node. Access to the runtime socket is effectively root on the node.

Which kube-proxy concern matters for security?

Answer: Its metrics and health endpoints should not be exposed beyond the node. kube-proxy runs privileged with host networking; keep its ports internal.

Where do Pods get their ServiceAccount tokens from in modern Kubernetes?

Answer: Short-lived, audience-bound tokens projected by the kubelet via the TokenRequest API. Bound tokens expire and are rotated; legacy auto-created token Secrets are no longer the default.

What should client-side security for kubectl users include?

Answer: Protecting kubeconfig files and their credentials; Short-lived credentials such as OIDC tokens. A kubeconfig is a key to the cluster.

Which storage concern matters for security?

Answer: Restricting hostPath volumes, which expose the node filesystem. hostPath can give a Pod access to sensitive node files; restricted Pod Security disallows it.

What does the container networking layer need for segmentation?

Answer: A CNI plugin that enforces NetworkPolicy. Without enforcement, NetworkPolicies are silently ignored.

Why is a Pod with hostNetwork: true risky?

Answer: It shares the node’s network namespace, bypassing Pod network isolation. It can see and bind node interfaces and reach node-local services.

What are the three Pod Security Admission modes?

Answer: enforce; audit; warn. enforce rejects; audit records in the audit log; warn returns a warning to the user.

How do you apply a Pod Security Standard to a namespace?

Answer: Label it, e.g. pod-security.kubernetes.io/enforce=baseline. Pod Security Admission reads namespace labels; PodSecurityPolicy was removed in v1.25.

Which settings does the restricted standard require?

Answer: runAsNonRoot; Dropping all capabilities; allowPrivilegeEscalation: false. Restricted also requires a seccomp profile (RuntimeDefault or Localhost).

Which authentication methods does Kubernetes support for users?

Answer: X.509 client certificates; OIDC tokens. Kubernetes has no User object — identities come from certificates, tokens or an IdP.

What is the difference between authentication and authorization?

Answer: Authentication proves who you are; authorization decides what you may do. The API server authenticates, then authorizes, then runs admission.

What does a ClusterRoleBinding do?

Answer: Grants a ClusterRole across the whole cluster. Use a RoleBinding to grant a ClusterRole inside a single namespace instead.

Why is the "escalate" or "bind" verb on roles sensitive?

Answer: It lets a user grant permissions they do not have themselves. RBAC normally prevents privilege escalation; these verbs bypass that check.

Which permission effectively grants access to all Secrets in a namespace?

Answer: Creating Pods in that namespace. A Pod can mount any Secret in its namespace.

How can Secrets be kept outside etcd?

Answer: An external secret store via a CSI driver or external secrets operator. Vaults and cloud secret managers can supply secrets at runtime.

What is a good practice for Secret RBAC?

Answer: Grant get on specific Secrets by name instead of list/watch on all. list and watch reveal every Secret’s content in the namespace.

What do audit logs record?

Answer: API requests: who made them, what they did, when and the result. Audit policy levels control how much of each request is kept.

Which audit level records request metadata only, without bodies?

Answer: Metadata. Metadata logs user, verb, resource and timestamp.

A namespace has a NetworkPolicy with podSelector: {} and policyTypes [Ingress] and no rules. What happens?

Answer: All ingress to Pods in that namespace is denied. That is the standard default-deny ingress policy.

Can a NetworkPolicy select traffic by namespace?

Answer: Yes, with a namespaceSelector. from/to entries can combine namespaceSelector and podSelector.

Why separate tenants into different namespaces?

Answer: To scope RBAC, quotas and network policies per tenant. Namespaces are a soft boundary; stronger isolation needs more (nodes, sandboxes, separate clusters).

What does automountServiceAccountToken: false achieve?

Answer: The Pod gets no API token unless it needs one. Fewer credentials in Pods means less to steal.

Which object limits total CPU and memory a namespace can request?

Answer: ResourceQuota. LimitRange sets per-Pod defaults and bounds; ResourceQuota caps the namespace total.

In the STRIDE model, a stolen ServiceAccount token used to impersonate a workload is…

Answer: Spoofing. Spoofing is pretending to be someone else.

An attacker modifies a container image in the registry. Which STRIDE category?

Answer: Tampering. Image signing and verification mitigate tampering.

A user deletes resources and there is no record of who did it. Which threat is this?

Answer: Repudiation. Audit logging counters repudiation.

A container escape gives an attacker root on the node. Which category?

Answer: Elevation of privilege. Privileged settings and kernel vulnerabilities enable it.

What is lateral movement in a cluster?

Answer: Using one compromised workload to reach and attack others. NetworkPolicies, least privilege and mTLS limit it.

Which is a persistence technique in a cluster?

Answer: Creating a hidden CronJob or DaemonSet that keeps re-running malicious code. Attackers use workloads, webhooks or static Pods to survive restarts.

A mutating admission webhook controlled by an attacker could…

Answer: Inject malicious containers into every new Pod. Mutating webhooks can change any object they intercept — protect who can create them.

Which trust boundary does a container escape cross?

Answer: Container to host node. The node is the next boundary after the container.

What is the impact of an unauthenticated kubelet API?

Answer: Anyone who reaches it can run commands in Pods on that node. The kubelet API includes exec and logs endpoints.

Which control limits damage from a malicious container image already running?

Answer: A read-only root filesystem; Dropping all capabilities. Hardening the runtime context restricts what malicious code can do.

What is data exfiltration and a control against it?

Answer: Sending sensitive data out of the cluster — restrict egress with NetworkPolicies. Default-deny egress makes unexpected outbound connections fail and stand out.

Why can a compromised CI system be a cluster threat?

Answer: It often holds deploy credentials and can push changed artifacts. Supply chain attacks frequently target the build and deploy pipeline.

What does an SBOM help you answer after a new CVE is published?

Answer: Which of your images contain the affected package. A Software Bill of Materials lists every component in an artifact.

What does SLSA describe?

Answer: Levels of supply chain integrity, especially build provenance. SLSA (Supply-chain Levels for Software Artifacts) defines provenance requirements per level.

What does signing an image with Sigstore cosign provide?

Answer: Proof of who built it and that it has not changed. Admission policies can then verify signatures before Pods run.

Where should image signature verification be enforced?

Answer: At admission, before Pods are created. Kyverno, Gatekeeper or an image policy webhook can reject unsigned images.

Which policy engines are commonly used for Kubernetes admission control?

Answer: Kyverno; OPA Gatekeeper. Both plug into admission via webhooks.

What does a ValidatingAdmissionPolicy use to express rules natively in the API server?

Answer: CEL (Common Expression Language). It avoids running a webhook for many validation needs.

Which observability signal is most useful for detecting a suspicious kubectl exec?

Answer: API server audit logs. exec calls appear as pods/exec requests in the audit log.

What does a runtime security tool like Falco detect?

Answer: Suspicious behaviour from system calls, e.g. a shell spawned in a container. It alerts on behaviour, not on known signatures.

What does PKI provide inside a Kubernetes cluster?

Answer: Certificates that authenticate and encrypt component communication. kubeadm creates the cluster CA and component certificates.

What must be done about expiring control-plane certificates?

Answer: Rotate or renew them before they expire. kubeadm certs check-expiration and kubeadm certs renew help; upgrades also renew them.

How does a service mesh help with zero-trust networking?

Answer: Every request is authenticated and authorized per workload identity, not by network location. Identity-based mTLS plus authorization policies.

What is an image scanning policy gate?

Answer: Blocking images with critical vulnerabilities from being deployed. Scan results can feed admission or pipeline gates.

What is the CIS Kubernetes Benchmark?

Answer: Consensus-based secure configuration recommendations for Kubernetes. kube-bench checks a cluster against it.

Which tool runs CIS Kubernetes Benchmark checks?

Answer: kube-bench. kube-bench reports PASS/FAIL/WARN per recommendation.

What is threat modelling used for?

Answer: Systematically identifying what could go wrong and prioritizing mitigations. Frameworks like STRIDE give it structure.

What does the MITRE ATT&CK framework catalogue?

Answer: Real-world attacker tactics and techniques. It includes a matrix for containers.

What is NIST SP 800-190?

Answer: NIST’s Application Container Security Guide. It covers risks and countermeasures for images, registries, orchestrators, containers and hosts.

What is supply chain compliance about?

Answer: Proving where artifacts came from and what is inside them (provenance, SBOMs). Regulations increasingly require SBOMs and provenance.

Why automate compliance checks in pipelines and clusters?

Answer: Continuous, repeatable evidence instead of occasional manual audits. Policy-as-code and scanners produce evidence on every change.

What does CVSS provide?

Answer: A standard severity score for vulnerabilities. Scanners report CVSS scores to help prioritize fixes.

In the 4Cs of cloud native security, which layer is the outermost?

Answer: Cloud. Cloud → Cluster → Container → Code. Each inner layer depends on the security of the ones around it.

On a managed Kubernetes service, which is still the customer’s responsibility?

Answer: RBAC for your users and workloads; The security of the container images you deploy. The provider secures what it operates; everything you configure and deploy remains yours.

Which component, if compromised, exposes every Secret in the cluster at once?

Answer: etcd. Secrets are stored in etcd. Protect it with mTLS, network isolation and encryption at rest.

Which admission plugin limits a kubelet to modifying only its own Node and the Pods bound to it?

Answer: NodeRestriction. Combined with the Node authorizer, NodeRestriction stops a compromised kubelet from tampering with other nodes.

Which Pod Security Standard is the most restrictive?

Answer: restricted. privileged (no restrictions) → baseline (blocks known escalations) → restricted (current hardening best practice).

Why is a Kubernetes Secret not secure just because it is a Secret?

Answer: Its data is only base64-encoded, so anyone who can read it can decode it. Encode ≠ encrypt. Restrict access with RBAC and enable encryption at rest or use an external secret store.

RBAC has no deny rules. So how is access denied?

Answer: Anything not explicitly granted by some binding is denied. RBAC permissions are purely additive on top of a default deny.

Which Pod settings most directly let a container break out onto its node?

Answer: privileged: true; A hostPath mount of /. Privileged mode and mounting the host filesystem hand the container the node. The other settings reduce risk.

One tenant’s runaway workload consumes all cluster resources. Which threat is this, and a mitigation?

Answer: Denial of service — ResourceQuotas and limits per namespace. Resource exhaustion is DoS; quotas and limits bound what one tenant can consume.

Where in the request path can a policy engine reject an unsigned image?

Answer: Admission control (an admission webhook). Admission runs after authn/authz and before the object is stored, which is where Kyverno or Gatekeeper act (Kyverno verifies images in its admission webhooks and can pin them to digests).

What does a service mesh most directly add to service-to-service security?

Answer: Mutual TLS with workload identities. Sidecars or node proxies authenticate both sides and encrypt the traffic between them.

Which framework is a threat modelling method rather than a configuration benchmark?

Answer: STRIDE. STRIDE categorizes threats; CIS and PSS prescribe configuration, kube-bench checks against CIS.