Month End Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 75only

Linux Foundation Cilium-Associate Cilium Certified AssociateCCA Exam Practice Test

Demo: 18 questions
Total 60 questions

Cilium Certified AssociateCCA Questions and Answers

Question 1

You are creating a Cilium network policy for pods with the label app: frontend . The policy should allow all pods with that label to communicate with destinations inside 192.168.e.e/24 and using TCP on port 8888.

For example:

� Traffic to 192.168.9.23:8888 should be allowed

� Traffic to 192.168.10.5:8888 should be denied.

� Traffic to 192.168.9.12:5606 should be denied.

Which of the following policies is correct?

A)

Option A

B)

Option B

C)

Option C

D)

Option D

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 2

In which use case can the Cilium Service Mesh exclusively utilize eBPF without requiring a proxy such as Envoy?

Options:

A.

For traffic management features, such as gRPC parsing.

B.

For traffic management features, such as DNS parsing.

C.

For traffic management features, such as Kafka parsing.

D.

For traffic management features, such as Layer 3/Layer 4 forwarding.

Question 3

What would be a benefit of using remote service affinity in a Cluster Mesh deployment?

Options:

A.

It would enable operators to avoid the unavailability of an application by temporarily forwarding traffic to local clusters while the remote application is being updated.

B.

It would enable operators to avoid the unavailability of an application by using the Egress Gateway to send the traffic to a remote destination.

C.

It would enable operators to avoid the unavailability of an application by load-balancing traffic to all endpolnts across both local and remote clusters.

D.

It would enable operators to avoid the unavailability of an application by temporarily forwarding traffic to remote clusters while the local application is being updated.

Question 4

Which component manages the allocation of per-node PodCIDRs in the cluster-scope IPAM (IP address management) mode?

Options:

A.

Kubernetes through the host-scope IPAM.

B.

The Cllium Agents on the nodes.

C.

Cilium Operator via CiliumNode resource.

D.

Kubernetes through the Node resource.

Question 5

How does Cilium primarily improve security in Kubernetes clusters?

Options:

A.

By using API Gateway configurations.

B.

By securing and encrypting database data.

C.

By providing backup solutions for persistent volumes.

D.

By implementing network policies at multiple OSI model layers.

Question 6

What is true about WireGuard encryption on Cilium?

Options:

A.

Packets are encrypted when they are destined to the same node from which they were sent. This is to ensure confidentiality of traffic within the node.

B.

It provides encryption for node-to-node, pod-to-node, node-to-pod, and pop-to-pod traffic as long as the pods are on different nodes.

C.

When running in the tunneling mode, pod-to-pod traffic will be sent over the WireGuard tunnel before being transmitted over the overlay tunnel.

D.

When WireGuard is enabled in Cilium, each pod will establish a secure WireGuard tunnel between it and all other known pods in the cluster.

Question 7

Review the Cilium Network Policy in the YAML file.

It was deployed in the ns-cca namespace on cluster1

Cluster Mesh CiliumNetworkPolicy exhibit

Which statement Is correct?

Options:

A.

This policy will allow traffic from a Pod named ship in ns-cca namespace in clusterl to a Pod named base in ns-cca namespace in cluster2.

B.

This policy will allow traffic from a Pod named ship in ns-cca namespace in clusterl to a Pod named base in default namespace in cluster2.

C.

This policy will deny traffic from a Pod named ship in ns-cca namespace in clusterl to a Pod named base in ns-cca namespace in cluster2.

D.

This policy will deny traffic from a Pod named ship in ns-cca namespace in clusterl to a Pod named base in default namespace in cluster2.

Question 8

Which proxy does Cilium use to enforce HTTP and other Layer 7 (L7) policies specified in network policies for the cluster?

Options:

A.

HAProxy

B.

Squid

C.

Linkerd2-proxy

D.

Envoy

Question 9

What is NOT a valid description of the sidecar-based model?

Options:

A.

pod start-up time can be significantly slowed by the Injection of sidecars, or worse, It can cause race conditions or other instabilities.

B.

With sidecars, the instrumentation container is Injected into each pod. The application pod has to be restarted for the sidecar to be added.

C.

The sidecar approach used by service meshes forces the instrumentation into the source code of the application.

D.

Using a networking sidecar means that all traffic to and from the application has to travel through the network stack to reach a proxy container

Question 10

You need to expose an application over HTTPS on your Cilium-managed Kubernetes cluster

The security team has specifically asked for traffic to be encrypted all the way from the external clients to the Service.

Which option should you use?

Options:

A.

Enable the Gateway API feature and use the TLS Terminate mode and HTTPRoute route type.

B.

Enable the Ingress feature and use the TLS Passthrough mode and TLSRoute route type.

C.

Enable the Ingress feature and use the TLS Terminate mode and HTTPRoute route type.

D.

Enable the Gateway API feature and use the TLS Passthrough mode and TLSRoute route type.

Question 11

What is the correct statement about the masquerading feature?

Options:

A.

The iptables-based masquerading is the most efficient Implementation.

B.

It replaces the source IP of traffic leaving the cluster to the node's IP address.

C.

It is comparable to Destination Network Address Translation (DNAT).

D.

The eBPF-based masquerading is supported on all kernel versions.

Question 12

A user has set up a global service as a Kubernetes user with access to clusters in a Cilium Cluster Mesh. They notice that all traffic is going to remote backend pods. What is a possible explanation?

Options:

A.

There are no local endpoints matching the selector for the service.

B.

The cluster is not part of the Cilium Cluster Mesh.

C.

The service.cilium.io/affinity: "none" annotation Is set on the service.

D.

The service.cilium.io/shared: "false" annotation is set on the service.

Question 13

Cilium status exhibit

Based on the cilium status output above, what is correct about the Cilium deployment?

For accessibility, the output of the command has been edited.

Options:

A.

Observability of network flows via a graphical user interface has yet to be enabled for this particular cluster

B.

The component responsible for registering the CRDs used by Cilium is healthy.

C.

The operator has been deployed as a DaemonSet.

D.

Only a single operator replica can be deployed on the cluster.

Question 14

What is true about Layer 7 protocol visibility in Cilium?

Options:

A.

DNS visibility in available in the ingress direction only.

B.

It can be enabled by deploying a standard Kubernetes network policy.

C.

It results in traffic being proxied through an Envoy instance.

D.

It supports any Layer 7 protocols, including SSH, Telnet and FTP.

Question 15

Which statement is true of both the Ingress Controller and Gateway API?

Options:

A.

It provides portable Layer 7 north-south routing logic for Kubernetes workloads.

B.

Its routing logic can be restricted to a single namespace.

C.

It is role-oriented, with some resources for administrators and others for users.

D.

Its features are commonly extended by using resource annotations.

Question 16

Which component is embedded in the Cilium Agent and retrieves eBPF-based visibility from Cilium?

Options:

A.

Cilium CNI

B.

Cilium Operator

C.

Hubble Relay

D.

Hubble Server

Question 17

The application team would like to observe egress traffic with application level information for workloads running in a Cilium based Kubernetes Cluster Which features would offer this without the need for additional tooling?

Options:

A.

Cilium Load Balancing

B.

Fluentd and Grafana

C.

Kubernetes Network Policies

D.

Hubble Ul and CLI

Question 18

Which component, when available, is able to handle IPAM requests?

Options:

A.

Cilium Agent

B.

Cilium API Server

C.

Cilium Operator

D.

Cilium CNIPIugin

Demo: 18 questions
Total 60 questions