75only - Ends in 0d 00h 00m 00s - Coupon code = 75only

Pass the Linux Foundation Cloud & Containers Cilium-Associate Questions and answers with Dumpstech

Exam Cilium-Associate Premium Access

View all detail and faqs for the Cilium-Associate exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

You are creating a Cilium network policy for pods with the label app: frontend . The policy should allow all pods with that label to communicate with destinations inside 192.168.e.e/24 and using TCP on port 8888.

For example:

� Traffic to 192.168.9.23:8888 should be allowed

� Traffic to 192.168.10.5:8888 should be denied.

� Traffic to 192.168.9.12:5606 should be denied.

Which of the following policies is correct?

A)

Question # 1

Option A

B)

Question # 1

Option B

C)

Question # 1

Option C

D)

Question # 1

Option D

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Questions # 2:

Which statement is true about Mutual Authentication with Cilium?

Options:

A.

By default, data of SPIRE is stored In memory.

B.

Cilium's Mutual authentication has been validated with SPIFFE, the production-ready implementation of SPIRE.

C.

Enabling Mutual Authentication on Cilium requires installing, managing, and configuring a SPIRE server.

D.

Through SPIRE, TLS certificates are automatically managed and frequently rotated.

Questions # 3:

Which component, when available, is able to handle IPAM requests?

Options:

A.

Cilium Agent

B.

Cilium API Server

C.

Cilium Operator

D.

Cilium CNIPIugin

Questions # 4:

Which one of the following Cilium Network Policies follow the correct syntax?

A)

Question # 4

Question 17 option A

B)

Question # 4

Question 17 option B

C)

Question # 4

Question 17 option C

D)

Question # 4

Question 17 option D

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Questions # 5:

Which one of the following commands will correctly display show the Cilium configuration?

Options:

A.

cilium config view

B.

cilium show config

C.

kubectl describe ciliumconfig.ciliu � .io

D.

cilium show run

Questions # 6:

Which of these observability features is NOT supported by Hubble?

Options:

A.

Hubble Is able to filter flows based on a given Kubernetes node name.

B.

Hubble Is able to provide Layer 7 visibility In eBPF, without the need for a proxy.

C.

Hubble is able to observe by HTTP Status code (like "404" or "200").

D.

Hubble is able to filter traffic based on the network policy verdict.

Questions # 7:

A user has set up a global service as a Kubernetes user with access to clusters in a Cilium Cluster Mesh. They notice that all traffic is going to remote backend pods. What is a possible explanation?

Options:

A.

There are no local endpoints matching the selector for the service.

B.

The cluster is not part of the Cilium Cluster Mesh.

C.

The service.cilium.io/affinity: "none" annotation Is set on the service.

D.

The service.cilium.io/shared: "false" annotation is set on the service.

Questions # 8:

You are managing two Kubernetes clusters, labeled as Cluster A and Cluster B, both of which have Cilium installed. You want to mesh Cluster A and Cluster B together The following characteristics define these clusters:

� Both clusters are configured In encapsulation mode.

� The PodCIDR ranges differ: Cluster A uses 192.168.0.0723, while Cluster B uses 192.168.2.0/24.

� There is IP connectivity between the nodes in all clusters using their respective InternallP addresses.

� The network infrastructure between the clusters enables inter-cluster communication.

� Cluster A runs Kubernetes version 1.28, and Cluster B runs Kubernetes version 1.27.

� Cilium versions also differ, with Cluster A using version 1.14 and Cluster B using version 1.13.

� Both clusters share the same cluster name and cluster ID.

� The Cilium certificate authority differs between Cluster A and Cluster B.

Is it possible to create a cluster mesh given the conditions?

Options:

A.

Yes. but you need to change the cluster name and cluster ID before

B.

No, Cilium certificate authority must be the same to deploy a cluster mesh. You cannot change that after installation

C.

No. cluster name and cluster ID must be different. You cannot change that after installation.

D.

Yes, but you need to upgrade cilium version of Cluster B

Questions # 9:

Which command is used to enable logging at the debug log level of Cilium agents7

Options:

A.

cilium log level --set=debug

B.

cilium logging.level=debug

C.

cilium config set debug true

D.

cilium logging debug

Questions # 10:

This an Ingress configuration. What is the equivalent Gateway API configuration?

Question # 10

Question 19 source Ingress

A)

Question # 10

Question 19 option A

B)

Question # 10

Question 19 option B

C)

Question # 10

Question 19 option C

D)

Question # 10

Question 19 option D

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions