Kubernetes and Cloud Native Security Associate
Practice questions and flashcards for the CNCF Kubernetes and Cloud Native Security Associate (KCSA) certification. Covers cluster setup and hardening (CIS benchmarks, etcd encryption, audit logging), system hardening (seccomp, AppArmor), workload security (pod security standards, Falco, Trivy, supply chain), threat detection, and compliance governance (OPA, Kyverno, policy as code).
| Domain | Weight | Items | Coverage |
|---|---|---|---|
Cluster Setup and Hardening | 17% | 100 items | |
System and Workload Security | 17% | 100 items | |
Kubernetes threat model and security policies | 13% | 76 items | |
Platform Security and Compliance | 13% | 76 items | |
Kubernetes cluster component security | 12% | 75 items | |
Platform security including supply chain | 12% | 75 items | |
Compliance and security frameworks | 8% | 51 items | |
Threat Detection and Response | 4% | 25 items | |
Cloud native runtime security | 4% | 24 items |
Invest in your career with this comprehensive study pack
Correct answer: AWS Systems Manager (State Manager or Compliance). This is one of 400 practice questions in the KCSA KCSA: Kubernetes and Cloud Native Security Associate pack on ReadRoost.
The KCSA KCSA: Kubernetes and Cloud Native Security Associate study pack on ReadRoost includes 400 practice questions and 202 flashcards, covering 9 exam domains including Cluster Setup and Hardening. Every question has a detailed explanation so you understand why each answer is right or wrong.
Yes. The KCSA KCSA: Kubernetes and Cloud Native Security Associate pack is mapped to the latest official exam objectives and is maintained by the ReadRoost team. You get flashcards with spaced repetition, timed practice exams, and AI-powered explanations.
CCA-F
540 questions ยท 300 flashcards
CNPE
549 questions ยท 327 flashcards
PDE
525 questions ยท 321 flashcards
PMLE
2037 questions ยท 1009 flashcards
A company needs to assess their Amazon EKS cluster nodes against the CIS Kubernetes Benchmark to identify security misconfigurations. Which AWS service should they use to automate these compliance scans and view remediation recommendations?