Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: w75best

Linux Foundation Cilium-Associate Dumps

Cilium Certified AssociateCCA Questions and Answers

Question 1

The application team would like to observe egress traffic with application level information for workloads running in a Cilium based Kubernetes Cluster Which features would offer this without the need for additional tooling?

Options:

A.

Cilium Load Balancing

B.

Fluentd and Grafana

C.

Kubernetes Network Policies

D.

Hubble Ul and CLI

Question 2

This an Ingress configuration. What is the equivalent Gateway API configuration?

as

Question 19 source Ingress

A)

as

Question 19 option A

B)

as

Question 19 option B

C)

as

Question 19 option C

D)

as

Question 19 option D

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 3

Please review the output of cilium status below and answer the question that follows. Please note, the output has been modified for accessibility purposes.

as

Question 2 cilium status exhibit

Assume the cluster is healthy. What is correct about the ci 1 ium status command output above?

Options:

A.

The Kubernetes cluster where Cilium has been deployed should consist of four nodes.

B.

When specific Cilium features require Layer 7 processing, the Cilium agent starts an Envoy proxy as a separate process within the Cilium agent pod.

C.

The component that allows you to query multiple Hubble instances simultaneously and aggregate the results is unhealthy.

D.

Cilium has been installed and configured in a multi-cluster deployment model to provide load balancing and service discovery.

Question 4

The Cilium Agent is deployed as part of the Cilium installation. What of the following is true about the Cilium Agent?

Options:

A.

Cilium Agent registers the Custom Resource Definitions that Cilium uses.

B.

Cilium Agent creates the CiliumEndpoint objects for each pod in the cluster.

C.

Cilium Agent manages IP addresses for LoadBalancer type services (if LB IPAM is used).

D.

Cilium Agent synchronizes Kubernetes nodes information to the shared KVStore.

Question 5

How does Cilium primarily improve security in Kubernetes clusters?

Options:

A.

By using API Gateway configurations.

B.

By securing and encrypting database data.

C.

By providing backup solutions for persistent volumes.

D.

By implementing network policies at multiple OSI model layers.

Question 6

Which Cilium configuration is recommended to help identify the correct configuration of network policies without interrupting workload communications?

Options:

A.

DNS enforcement mode

B.

HTTP audit mode

C.

Policy enforcement mode

D.

Policy audit mode

Question 7

What are the differences between Ingress and Gateway API?

Options:

A.

Ingress and Gateway API serve the same purpose, but they are Just different names for the same Kubernetes resource. Ingress is used in older Kubernetes versions, while Gateway API is the updated version for modern clusters, but the underlying functionality is identical.

B.

Ingress primarily targets exposing HTTP applications with a simple, declarative syntax. Gateway API exposes a more general API for proxying that can be used for more protocols than just HTTP, and models more infrastructure components to provide better deployment and management options for cluster operators.

C.

Cilium offers seamless integration with the Gateway API, enhancing Kubernetes networking and security through advanced features powered by eBPF. This integration provides a robust solution for network management. In contrast, Ingress relies on IPtables for its functionality.

D.

Gateway API is primarily used for internal cluster routing, while Ingress is exclusively for external traffic management. Gateway API does not support routing for internet-exposed services, whereas Ingress is specifically designed for that purpose.

Question 8

Among the definitions provided for the entities host, remote-node, cluster, and all, which description is accurate in the context of Cilium network policy?

Options:

A.

The host entity Includes the local host. This also includes all containers running in host networking mode on the local host.

B.

The remote-node entity represents endpoints not managed by Cilium. Unmanaged endpoints are considered part of the cluster and are included in the cluster entity.

C.

The cluster entity represents the kube-apiserver in a Kubernetes cluster. This entity represents both deployments of the kube-apiserver: within the cluster and outside of the cluster

D.

The all entity corresponds to all endpoints outside of the cluster. Allowing to all Is identical to allowing to CIDR 0.0.0.0/0.

Question 9

What is the purpose of the 12 Announcements" feature?

Options:

A.

To support Layer 2 multicast traffic within Kubernetes.

B.

To make services visible and reachable on the local area network.

C.

To provide DNS-based service discovery within the cluster.

D.

To enforce Layer 2-based network security policies.

Question 10

What does this Egress Gateway policy achieve?

as

Cilium Egress Gateway policy exhibit

Options:

A.

It would cause all traffic originating from pods with the org: empire and class: mediabot labels in the default namespace and destined to 192.168.19.0/24 to be routed through the gateway node with the node.kubemetes.io/name: egress-node label, which will then SNAT said traffic with the 10.168.60.100 egress IP

B.

It would cause all traffic sent to pods with the org: empire and class: mediabot labels In the default namespace and destined to 192.168.19.9/24 to be routed through the gateway node with the node.kubemetes.io/name: egress-node label, which will then DNAT said traffic with the 19.168.69.199 egress IP

C.

It would cause all traffic sent to pods with the org: empire and class: mediabot labels in the default namespace and destined to 192.168.10.0/24 to be routed through the gateway node with the node.kubernetes.io/name: egress-node label, which will then SNAT said traffic with the 10.168.60.180 egress IP

D.

It would cause all traffic originating from pods with the org: empire and class: nediabot labels in the default namespace and destined to 192.168.19.0/24 to be routed through the gateway node with the node.kubernetes.io/name: egress-node label, which will then DN AT said traffic with the 10.168.60.100 egress IP

Question 11

Which of these observability features is NOT supported by Hubble?

Options:

A.

Hubble Is able to filter flows based on a given Kubernetes node name.

B.

Hubble Is able to provide Layer 7 visibility In eBPF, without the need for a proxy.

C.

Hubble is able to observe by HTTP Status code (like "404" or "200").

D.

Hubble is able to filter traffic based on the network policy verdict.

Question 12

What is correct about the Kubernetes Host Scope IP Address Management (IPAM) mode?

Options:

A.

It supports multiple CIDRs (Classless Inter-Domain Routing) per cluster

B.

It supports multiple CIDRs (Classless Inter-Domain Routing) per node.

C.

It can beset by using the ipam: crd configuration flag.

D.

It supports both tunnel and direct routing modes.

Question 13

Which statement is true about Mutual Authentication with Cilium?

Options:

A.

By default, data of SPIRE is stored In memory.

B.

Cilium's Mutual authentication has been validated with SPIFFE, the production-ready implementation of SPIRE.

C.

Enabling Mutual Authentication on Cilium requires installing, managing, and configuring a SPIRE server.

D.

Through SPIRE, TLS certificates are automatically managed and frequently rotated.

Question 14

Why is the iptables implementation of kube-proxy less scalable than eBPF?

Options:

A.

eBPF makes use of the kernel, while iptables does not.

B.

Iptables's complexity is linear while eBPF Is constant-time.

C.

Iptables is incompatible with IPv6 services in Kubernetes.

D.

Iptables is incompatible with eXpressDataPath for smartNICs.

Question 15

Which statement is true of both the Ingress Controller and Gateway API?

Options:

A.

It provides portable Layer 7 north-south routing logic for Kubernetes workloads.

B.

Its routing logic can be restricted to a single namespace.

C.

It is role-oriented, with some resources for administrators and others for users.

D.

Its features are commonly extended by using resource annotations.

Question 16

What is true about WireGuard encryption on Cilium?

Options:

A.

Packets are encrypted when they are destined to the same node from which they were sent. This is to ensure confidentiality of traffic within the node.

B.

It provides encryption for node-to-node, pod-to-node, node-to-pod, and pop-to-pod traffic as long as the pods are on different nodes.

C.

When running in the tunneling mode, pod-to-pod traffic will be sent over the WireGuard tunnel before being transmitted over the overlay tunnel.

D.

When WireGuard is enabled in Cilium, each pod will establish a secure WireGuard tunnel between it and all other known pods in the cluster.

Question 17

If you are required to block ingress traffic from external IPs for all pods in your cluster, which of the following network policies would be the best fit?

Options:

A.

CiliumNetworkPolicy

B.

CiliumGlobalPolicy

C.

NetworkPolicy

D.

CiliumClusterWideNetworkPolicy

Question 18

Which command is used to enable logging at the debug log level of Cilium agents7

Options:

A.

cilium log level --set=debug

B.

cilium logging.level=debug

C.

cilium config set debug true

D.

cilium logging debug

Page: 1 / 6
Total 60 questions