Weekend Special Sale 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale75best

Free Linux Foundation Cilium-Associate Practice Exam with Questions & Answers | Set: 2

Questions 11

Which Cilium configuration is recommended to help identify the correct configuration of network policies without interrupting workload communications?

Options:
A.

DNS enforcement mode

B.

HTTP audit mode

C.

Policy enforcement mode

D.

Policy audit mode

Linux Foundation Cilium-Associate Premium Access
Questions 12

Which Cilium command should you execute to gather network-related troubleshooting information from your Kubernetes cluster?

Options:
A.

cilium bugtool

B.

cilium debuginfo

C.

cilium status --verbose

D.

cilium sysduwp

Questions 13

Which statement is true of both the Ingress Controller and Gateway API?

Options:
A.

It provides portable Layer 7 north-south routing logic for Kubernetes workloads.

B.

Its routing logic can be restricted to a single namespace.

C.

It is role-oriented, with some resources for administrators and others for users.

D.

Its features are commonly extended by using resource annotations.

Questions 14

What is true about WireGuard encryption on Cilium?

Options:
A.

Packets are encrypted when they are destined to the same node from which they were sent. This is to ensure confidentiality of traffic within the node.

B.

It provides encryption for node-to-node, pod-to-node, node-to-pod, and pop-to-pod traffic as long as the pods are on different nodes.

C.

When running in the tunneling mode, pod-to-pod traffic will be sent over the WireGuard tunnel before being transmitted over the overlay tunnel.

D.

When WireGuard is enabled in Cilium, each pod will establish a secure WireGuard tunnel between it and all other known pods in the cluster.

Questions 15

Which proxy does Cilium use to enforce HTTP and other Layer 7 (L7) policies specified in network policies for the cluster?

Options:
A.

HAProxy

B.

Squid

C.

Linkerd2-proxy

D.

Envoy

Questions 16

Which affirmation is true about eBPF host-routing?

Options:
A.

eBPF host-routing ensures that traffic is distributed evenly across multiple backend services, improving the overall efficiency of load balancing.

B.

eBPF host-routing allows the network stack to prepare larger GSO (transmit) and GRO (receive) packets to reduce the number of times the stack is traversed, which improves performance and latency.

C.

eBPF host-routing allows bypassing iptables and upper stack overhead in the host namespace and some context-switching overhead when traversing through the Virtual Ethernet pairs.

D.

eBPF host-routing is particularly suitable when pods are exposed behind Kubernetes Services, which face external clients from the Internet.

Questions 17

Among the definitions provided for the entities host, remote-node, cluster, and all, which description is accurate in the context of Cilium network policy?

Options:
A.

The host entity Includes the local host. This also includes all containers running in host networking mode on the local host.

B.

The remote-node entity represents endpoints not managed by Cilium. Unmanaged endpoints are considered part of the cluster and are included in the cluster entity.

C.

The cluster entity represents the kube-apiserver in a Kubernetes cluster. This entity represents both deployments of the kube-apiserver: within the cluster and outside of the cluster

D.

The all entity corresponds to all endpoints outside of the cluster. Allowing to all Is identical to allowing to CIDR 0.0.0.0/0.

Questions 18

What is the correct statement about the masquerading feature?

Options:
A.

The iptables-based masquerading is the most efficient Implementation.

B.

It replaces the source IP of traffic leaving the cluster to the node's IP address.

C.

It is comparable to Destination Network Address Translation (DNAT).

D.

The eBPF-based masquerading is supported on all kernel versions.