Month End Sale Special Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: CFsave75

Pass the Linux Foundation Cloud & Containers Cilium-Associate Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

What is a correct statement related to BIG TCP, an eBPF-based feature in Cilium?

Options:

A.

BIG TCP requires updating the Maximum Transmission Unit (MTU) across the network.


B.

While BIG TCP increases the transactions count, it causes higher latency between pods.


C.

BIG TCP addresses the limitation in the size of the packets, caused by the 16-bit length field in the IP header.


D.

BIG TCP is incompatible with features like GRO (Generic Receive Offload) and TSO (Transmit Segmentation Offload).


Expert Solution
Questions # 2:

Which Cilium command should you execute to gather network-related troubleshooting information from your Kubernetes cluster?

Options:

A.

cilium bugtool


B.

cilium debuginfo


C.

cilium status --verbose


D.

cilium sysduwp


Expert Solution
Questions # 3:

The application team would like to observe egress traffic with application level information for workloads running in a Cilium based Kubernetes Cluster Which features would offer this without the need for additional tooling?

Options:

A.

Cilium Load Balancing


B.

Fluentd and Grafana


C.

Kubernetes Network Policies


D.

Hubble Ul and CLI


Expert Solution
Questions # 4:

What would be a benefit of using remote service affinity in a Cluster Mesh deployment?

Options:

A.

It would enable operators to avoid the unavailability of an application by temporarily forwarding traffic to local clusters while the remote application is being updated.


B.

It would enable operators to avoid the unavailability of an application by using the Egress Gateway to send the traffic to a remote destination.


C.

It would enable operators to avoid the unavailability of an application by load-balancing traffic to all endpolnts across both local and remote clusters.


D.

It would enable operators to avoid the unavailability of an application by temporarily forwarding traffic to remote clusters while the local application is being updated.


Expert Solution
Questions # 5:

As a Kubernetes user, you have deployed the following Cilium Network Policy:

Question # 5

Cilium Layer 7 network policy exhibit

The network policy is not having any effect. What Is the Issue?

Options:

A.

The backend and app-frontend workloads are in different namespaces.


B.

The app.kubernetes.io/name label should be referred to without the k8s: prefix


C.

Port 80 is a privileged port and cannot be used in network policies.


D.

The layer 7 rule requires the specification of the Layer 4 protocol in the ports section.


Expert Solution
Questions # 6:

You need to expose an application over HTTPS on your Cilium-managed Kubernetes cluster

The security team has specifically asked for traffic to be encrypted all the way from the external clients to the Service.

Which option should you use?

Options:

A.

Enable the Gateway API feature and use the TLS Terminate mode and HTTPRoute route type.


B.

Enable the Ingress feature and use the TLS Passthrough mode and TLSRoute route type.


C.

Enable the Ingress feature and use the TLS Terminate mode and HTTPRoute route type.


D.

Enable the Gateway API feature and use the TLS Passthrough mode and TLSRoute route type.


Expert Solution
Questions # 7:

How does Cilium primarily improve security in Kubernetes clusters?

Options:

A.

By using API Gateway configurations.


B.

By securing and encrypting database data.


C.

By providing backup solutions for persistent volumes.


D.

By implementing network policies at multiple OSI model layers.


Expert Solution
Questions # 8:

This an Ingress configuration. What is the equivalent Gateway API configuration?

Question # 8

Question 19 source Ingress

A)

Question # 8

Question 19 option A

B)

Question # 8

Question 19 option B

C)

Question # 8

Question 19 option C

D)

Question # 8

Question 19 option D

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 9:

A Kubernetes cluster is not currently running Cilium as a CNI, but the user would like to benefit from Hubbies observability capabilities on your cluster. Which one of the following options is NOT possible?

Options:

A.

Migrating to Cilium and Hubble by reconfiguring /etc/cni/net .6/ to point to Cilium and restarting the nodes, accepting an outage.


B.

Install Hubble on the cluster without Cilium. Hubble can be deployed in a standalone model by downloading and installing the Hubble binary


C.

Install Cilium and Hubble on top of the cluster in a CNI chaining model, without disrupting the existing CNI.


D.

Migrating to Cilium and Hubble on a node-by-node basis, without requiring a complete cluster outage, by using Dual Overlays.


Expert Solution
Questions # 10:

Which statement about Cilium's identity-based security model is correct?

Options:

A.

An endpoint identity Is identified by labels and is tied to a single namespace.


B.

Security is based on the identity of a pod, which is derived through labels.


C.

By using an IP-address security model, identities can be shared between pods.


D.

Cilium enforces security based on IP addresses as it provides better scalability and flexibility.


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions