Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 75epass

Exact2Pass Menu

Cilium Certified AssociateCCA

Last Update 1 hour ago Total Questions : 60

The Cilium Certified AssociateCCA content is now fully updated, with all current exam questions added 1 hour ago. Deciding to include Cilium-Associate practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our Cilium-Associate exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these Cilium-Associate sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Cilium Certified AssociateCCA practice test comfortably within the allotted time.

Question # 1

Which command is used to enable logging at the debug log level of Cilium agents7

A.

cilium log level --set=debug

B.

cilium logging.level=debug

C.

cilium config set debug true

D.

cilium logging debug

Question # 2

What is the default policy enforcement behavior?

A.

If any rule selects an Endpoint and the rule has an ingress section, the Endpoint goes Into default deny at egress. f any rule selects an Endpoint and the rule has an egress section, the Endpoint goes into default deny at ingress.

B.

If any rule selects an Endpoint and the rule has an ingress section, the Endpoint goes Into default allow at egress, f any rule selects an Endpoint and the rule has an egress section, the Endpoint goes into default allow at ingress.

C.

If any rule selects an Endpoint and the rule has an ingress section, the Endpoint goes Into default allow at Ingress, f any rule selects an Endpoint and the rule has an egress section, the Endpoint goes into default allow at egress.

D.

If any rule selects an Endpoint and the rule has an ingress section, the Endpoint goes into default deny at ingress. f any rule selects an Endpoint and the rule has an egress section, the Endpoint goes into default deny at egress.

Question # 3

As a Kubernetes user, you have deployed the following Cilium Network Policy:

Cilium Layer 7 network policy exhibit

The network policy is not having any effect. What Is the Issue?

A.

The backend and app-frontend workloads are in different namespaces.

B.

The app.kubernetes.io/name label should be referred to without the k8s: prefix

C.

Port 80 is a privileged port and cannot be used in network policies.

D.

The layer 7 rule requires the specification of the Layer 4 protocol in the ports section.

Question # 4

Among the definitions provided for the entities host, remote-node, cluster, and all, which description is accurate in the context of Cilium network policy?

A.

The host entity Includes the local host. This also includes all containers running in host networking mode on the local host.

B.

The remote-node entity represents endpoints not managed by Cilium. Unmanaged endpoints are considered part of the cluster and are included in the cluster entity.

C.

The cluster entity represents the kube-apiserver in a Kubernetes cluster. This entity represents both deployments of the kube-apiserver: within the cluster and outside of the cluster

D.

The all entity corresponds to all endpoints outside of the cluster. Allowing to all Is identical to allowing to CIDR 0.0.0.0/0.

Question # 5

What is an accurate description related to eBPF?

A.

After eBPF programs have been loaded, the host needs rebooting before the functionality can be applied.

B.

eBPF program can only be attached in ingress (inbound from the network interface).

C.

Network security tools based on eBPF can only police the containers' traffic as they are unable to access the host.

D.

eBPF programs could inspect the decrypted contents of encrypted traffic.

Question # 6

Which one of the following statements accurately describes the identity-based network security model used by Cilium?

A.

Security is based on the identity of a pod, which Is derived through its IP address. This identity cannot be shared between pods.

B.

Security is based on the identity of a pod, which is derived through annotations. This Identity can be shared between pods.

C.

Security is based on the identity of a pod, which is derived through labels. This identity can be shared between pods.

D.

Security is based on the identity of a pod. The security ID is manually set by the operator and cannot be shared between pods.

Question # 7

You want to consult the current Cilium configuration using the Cilium CLI. Which command should you use?

A.

cilium status

B.

cilium sysdump

C.

cilium context

D.

cilium config view

Question # 8

Which encapsulation protocols are supported when configuring Cilium in tunnel mode?

A.

MPLS and Geneve

B.

VXLAN and Geneve

C.

OTV and STT

D.

EVPN and VXLAN

Question # 9

What is true about Layer 7 protocol visibility in Cilium?

A.

DNS visibility in available in the ingress direction only.

B.

It can be enabled by deploying a standard Kubernetes network policy.

C.

It results in traffic being proxied through an Envoy instance.

D.

It supports any Layer 7 protocols, including SSH, Telnet and FTP.

Question # 10

You are creating a Cilium network policy for pods with the label app: frontend . The policy should allow all pods with that label to communicate with destinations inside 192.168.e.e/24 and using TCP on port 8888.

For example:

� Traffic to 192.168.9.23:8888 should be allowed

� Traffic to 192.168.10.5:8888 should be denied.

� Traffic to 192.168.9.12:5606 should be denied.

Which of the following policies is correct?

A)

Option A

B)

Option B

C)

Option C

D)

Option D

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Go to page: