Weekend Special Sale 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale75best

Free Linux Foundation Cilium-Associate Practice Exam with Questions & Answers

Questions 1

Which one of the following statements accurately describes the identity-based network security model used by Cilium?

Options:
A.

Security is based on the identity of a pod, which Is derived through its IP address. This identity cannot be shared between pods.

B.

Security is based on the identity of a pod, which is derived through annotations. This Identity can be shared between pods.

C.

Security is based on the identity of a pod, which is derived through labels. This identity can be shared between pods.

D.

Security is based on the identity of a pod. The security ID is manually set by the operator and cannot be shared between pods.

Linux Foundation Cilium-Associate Premium Access
Questions 2

Which statement is true about Mutual Authentication with Cilium?

Options:
A.

By default, data of SPIRE is stored In memory.

B.

Cilium's Mutual authentication has been validated with SPIFFE, the production-ready implementation of SPIRE.

C.

Enabling Mutual Authentication on Cilium requires installing, managing, and configuring a SPIRE server.

D.

Through SPIRE, TLS certificates are automatically managed and frequently rotated.

Questions 3

Which question does Hubble provide the information to answer?

Options:
A.

What is the configuration of Cilium B6P?

B.

Which container database query ran the longest?

C.

Which containers have the highest CPU utilization?

D.

Which services had connections blocked due to network policy?

Questions 4

If you are required to block ingress traffic from external IPs for all pods in your cluster, which of the following network policies would be the best fit?

Options:
A.

CiliumNetworkPolicy

B.

CiliumGlobalPolicy

C.

NetworkPolicy

D.

CiliumClusterWideNetworkPolicy

Questions 5

Which of these observability features is NOT supported by Hubble?

Options:
A.

Hubble Is able to filter flows based on a given Kubernetes node name.

B.

Hubble Is able to provide Layer 7 visibility In eBPF, without the need for a proxy.

C.

Hubble is able to observe by HTTP Status code (like "404" or "200").

D.

Hubble is able to filter traffic based on the network policy verdict.

Questions 6

Why is the iptables implementation of kube-proxy less scalable than eBPF?

Options:
A.

eBPF makes use of the kernel, while iptables does not.

B.

Iptables's complexity is linear while eBPF Is constant-time.

C.

Iptables is incompatible with IPv6 services in Kubernetes.

D.

Iptables is incompatible with eXpressDataPath for smartNICs.

Questions 7

The application team would like to observe egress traffic with application level information for workloads running in a Cilium based Kubernetes Cluster Which features would offer this without the need for additional tooling?

Options:
A.

Cilium Load Balancing

B.

Fluentd and Grafana

C.

Kubernetes Network Policies

D.

Hubble Ul and CLI

Questions 8

You need to expose an application over HTTPS on your Cilium-managed Kubernetes cluster

The security team has specifically asked for traffic to be encrypted all the way from the external clients to the Service.

Which option should you use?

Options:
A.

Enable the Gateway API feature and use the TLS Terminate mode and HTTPRoute route type.

B.

Enable the Ingress feature and use the TLS Passthrough mode and TLSRoute route type.

C.

Enable the Ingress feature and use the TLS Terminate mode and HTTPRoute route type.

D.

Enable the Gateway API feature and use the TLS Passthrough mode and TLSRoute route type.

Questions 9

What is correct about the Kubernetes Host Scope IP Address Management (IPAM) mode?

Options:
A.

It supports multiple CIDRs (Classless Inter-Domain Routing) per cluster

B.

It supports multiple CIDRs (Classless Inter-Domain Routing) per node.

C.

It can beset by using the ipam: crd configuration flag.

D.

It supports both tunnel and direct routing modes.

Questions 10

After enabling Layer 7 visibility, you can now observe DNS domains and FQDN in your Hubble logs, like the one below.

Nov 16 13:52:07.279: endor/xwing-9bd8f454d-m46mm:34706 (ID:3817) < > example.com:443 (ID:16777217) Policy denied DROPPED (TCP Flags SYN)

Which of these Hubble CLI commands could have returned the output above?

Options:
A.

hubble observe --to-fqdn example.con --from-namespace endor --to-port 443 --verdict DROPPED

B.

hubble obs erve --to-fqdn example.con --fro � -namespace endor --to-port 80 --verdict DROPPED

C.

hubble observe --to-fqdn example.cow --from-namespace kube-system --to-port 443 --verdict DROPPED

D.

hubble observe --to-fqdn example.co* --from-namespace endor --to-port 443 --verdict FORWARDED