Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: my75ex

Home > Linux Foundation > Cloud & Containers > Cilium-Associate

Cilium-Associate Cilium Certified AssociateCCA Question and Answers

Question # 4

Which of these observability features is NOT supported by Hubble?

A.

Hubble Is able to filter flows based on a given Kubernetes node name.

B.

Hubble Is able to provide Layer 7 visibility In eBPF, without the need for a proxy.

C.

Hubble is able to observe by HTTP Status code (like "404" or "200").

D.

Hubble is able to filter traffic based on the network policy verdict.

Full Access
Question # 5

What does this Egress Gateway policy achieve?

Cilium Egress Gateway policy exhibit

A.

It would cause all traffic originating from pods with the org: empire and class: mediabot labels in the default namespace and destined to 192.168.19.0/24 to be routed through the gateway node with the node.kubemetes.io/name: egress-node label, which will then SNAT said traffic with the 10.168.60.100 egress IP

B.

It would cause all traffic sent to pods with the org: empire and class: mediabot labels In the default namespace and destined to 192.168.19.9/24 to be routed through the gateway node with the node.kubemetes.io/name: egress-node label, which will then DNAT said traffic with the 19.168.69.199 egress IP

C.

It would cause all traffic sent to pods with the org: empire and class: mediabot labels in the default namespace and destined to 192.168.10.0/24 to be routed through the gateway node with the node.kubernetes.io/name: egress-node label, which will then SNAT said traffic with the 10.168.60.180 egress IP

D.

It would cause all traffic originating from pods with the org: empire and class: nediabot labels in the default namespace and destined to 192.168.19.0/24 to be routed through the gateway node with the node.kubernetes.io/name: egress-node label, which will then DN AT said traffic with the 10.168.60.100 egress IP

Full Access
Question # 6

You want to consult the current Cilium configuration using the Cilium CLI. Which command should you use?

A.

cilium status

B.

cilium sysdump

C.

cilium context

D.

cilium config view

Full Access
Question # 7

Which one of the following service mesh features and use cases is natively supported by Cilium?

A.

AP| request limiting

B.

API authorization

C.

Layer 7 Load Balancing of gRPC

D.

Fault injection, such as injection of delay

Full Access
Question # 8

Which Cilium command should you execute to gather network-related troubleshooting information from your Kubernetes cluster?

A.

cilium bugtool

B.

cilium debuginfo

C.

cilium status --verbose

D.

cilium sysduwp

Full Access
Question # 9

Why is the iptables implementation of kube-proxy less scalable than eBPF?

A.

eBPF makes use of the kernel, while iptables does not.

B.

Iptables's complexity is linear while eBPF Is constant-time.

C.

Iptables is incompatible with IPv6 services in Kubernetes.

D.

Iptables is incompatible with eXpressDataPath for smartNICs.

Full Access
Question # 10

Which of these is true of Cilium Cluster Mesh and Network Policies?

A.

Cilium Network Policies can be used to allow traffic targeting workloads in different clusters of the mesh.

B.

Cilium Network Policies can be used to set up encryption between multiple clusters in a Cilium Cluster Mesh.

C.

Cilium Network Policies can be used to set up load-balancing between multiple clusters in a Cilium Cluster Mesh.

D.

Cilium Network Policies can be used to set up mutual authentication between multiple clusters in a Cilium Cluster Mesh.

Full Access
Question # 11

Which statement is true about Mutual Authentication with Cilium?

A.

By default, data of SPIRE is stored In memory.

B.

Cilium's Mutual authentication has been validated with SPIFFE, the production-ready implementation of SPIRE.

C.

Enabling Mutual Authentication on Cilium requires installing, managing, and configuring a SPIRE server.

D.

Through SPIRE, TLS certificates are automatically managed and frequently rotated.

Full Access
Question # 12

Which one of the following Cilium Network Policies follow the correct syntax?

A)

Question 17 option A

B)

Question 17 option B

C)

Question 17 option C

D)

Question 17 option D

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 13

A user has set up a global service as a Kubernetes user with access to clusters in a Cilium Cluster Mesh. They notice that all traffic is going to remote backend pods. What is a possible explanation?

A.

There are no local endpoints matching the selector for the service.

B.

The cluster is not part of the Cilium Cluster Mesh.

C.

The service.cilium.io/affinity: "none" annotation Is set on the service.

D.

The service.cilium.io/shared: "false" annotation is set on the service.

Full Access
Question # 14

Which statement is true of both the Ingress Controller and Gateway API?

A.

It provides portable Layer 7 north-south routing logic for Kubernetes workloads.

B.

Its routing logic can be restricted to a single namespace.

C.

It is role-oriented, with some resources for administrators and others for users.

D.

Its features are commonly extended by using resource annotations.

Full Access
Question # 15

Which Cilium configuration is recommended to help identify the correct configuration of network policies without interrupting workload communications?

A.

DNS enforcement mode

B.

HTTP audit mode

C.

Policy enforcement mode

D.

Policy audit mode

Full Access
Question # 16

What are the differences between Ingress and Gateway API?

A.

Ingress and Gateway API serve the same purpose, but they are Just different names for the same Kubernetes resource. Ingress is used in older Kubernetes versions, while Gateway API is the updated version for modern clusters, but the underlying functionality is identical.

B.

Ingress primarily targets exposing HTTP applications with a simple, declarative syntax. Gateway API exposes a more general API for proxying that can be used for more protocols than just HTTP, and models more infrastructure components to provide better deployment and management options for cluster operators.

C.

Cilium offers seamless integration with the Gateway API, enhancing Kubernetes networking and security through advanced features powered by eBPF. This integration provides a robust solution for network management. In contrast, Ingress relies on IPtables for its functionality.

D.

Gateway API is primarily used for internal cluster routing, while Ingress is exclusively for external traffic management. Gateway API does not support routing for internet-exposed services, whereas Ingress is specifically designed for that purpose.

Full Access
Question # 17

What is correct about this Cilium Network Policy?

Question 21 Cilium Network Policy exhibit

A.

It will allow all traffic to the Kubemetes DNS servers from any pod in the default namespace.

B.

It will allow all traffic to the Kubernetes DNS servers from any pod across all namespaces in the cluster

C.

It will deny all traffic to the Kubernetes DNS servers from any pod across all namespaces in the cluster.

D.

It will deny all traffic to the Kubernetes DNS servers from any pod in the default namespace.

Full Access
Question # 18

What is a correct statement related to BIG TCP, an eBPF-based feature in Cilium?

A.

BIG TCP requires updating the Maximum Transmission Unit (MTU) across the network.

B.

While BIG TCP increases the transactions count, it causes higher latency between pods.

C.

BIG TCP addresses the limitation in the size of the packets, caused by the 16-bit length field in the IP header.

D.

BIG TCP is incompatible with features like GRO (Generic Receive Offload) and TSO (Transmit Segmentation Offload).

Full Access