Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: certbig75

Cilium-Associate Exam Dumps - Linux Foundation Cloud & Containers Questions and Answers

Question # 4

Which affirmation is true about eBPF host-routing?

Options:

A.

eBPF host-routing ensures that traffic is distributed evenly across multiple backend services, improving the overall efficiency of load balancing.

B.

eBPF host-routing allows the network stack to prepare larger GSO (transmit) and GRO (receive) packets to reduce the number of times the stack is traversed, which improves performance and latency.

C.

eBPF host-routing allows bypassing iptables and upper stack overhead in the host namespace and some context-switching overhead when traversing through the Virtual Ethernet pairs.

D.

eBPF host-routing is particularly suitable when pods are exposed behind Kubernetes Services, which face external clients from the Internet.

Buy Now
Question # 5

What is the correct statement about the masquerading feature?

Options:

A.

The iptables-based masquerading is the most efficient Implementation.

B.

It replaces the source IP of traffic leaving the cluster to the node's IP address.

C.

It is comparable to Destination Network Address Translation (DNAT).

D.

The eBPF-based masquerading is supported on all kernel versions.

Buy Now
Question # 6

You need to expose an application over HTTPS on your Cilium-managed Kubernetes cluster

The security team has specifically asked for traffic to be encrypted all the way from the external clients to the Service.

Which option should you use?

Options:

A.

Enable the Gateway API feature and use the TLS Terminate mode and HTTPRoute route type.

B.

Enable the Ingress feature and use the TLS Passthrough mode and TLSRoute route type.

C.

Enable the Ingress feature and use the TLS Terminate mode and HTTPRoute route type.

D.

Enable the Gateway API feature and use the TLS Passthrough mode and TLSRoute route type.

Buy Now
Question # 7

Which component, when available, is able to handle IPAM requests?

Options:

A.

Cilium Agent

B.

Cilium API Server

C.

Cilium Operator

D.

Cilium CNIPIugin

Buy Now
Question # 8

What is true about Layer 7 protocol visibility in Cilium?

Options:

A.

DNS visibility in available in the ingress direction only.

B.

It can be enabled by deploying a standard Kubernetes network policy.

C.

It results in traffic being proxied through an Envoy instance.

D.

It supports any Layer 7 protocols, including SSH, Telnet and FTP.

Buy Now
Question # 9

If you are required to block ingress traffic from external IPs for all pods in your cluster, which of the following network policies would be the best fit?

Options:

A.

CiliumNetworkPolicy

B.

CiliumGlobalPolicy

C.

NetworkPolicy

D.

CiliumClusterWideNetworkPolicy

Buy Now
Question # 10

What is correct about the Kubernetes Host Scope IP Address Management (IPAM) mode?

Options:

A.

It supports multiple CIDRs (Classless Inter-Domain Routing) per cluster

B.

It supports multiple CIDRs (Classless Inter-Domain Routing) per node.

C.

It can beset by using the ipam: crd configuration flag.

D.

It supports both tunnel and direct routing modes.

Buy Now
Question # 11

Which statement is true of both the Ingress Controller and Gateway API?

Options:

A.

It provides portable Layer 7 north-south routing logic for Kubernetes workloads.

B.

Its routing logic can be restricted to a single namespace.

C.

It is role-oriented, with some resources for administrators and others for users.

D.

Its features are commonly extended by using resource annotations.

Buy Now
Question # 12

The Cilium Agent is deployed as part of the Cilium installation. What of the following is true about the Cilium Agent?

Options:

A.

Cilium Agent registers the Custom Resource Definitions that Cilium uses.

B.

Cilium Agent creates the CiliumEndpoint objects for each pod in the cluster.

C.

Cilium Agent manages IP addresses for LoadBalancer type services (if LB IPAM is used).

D.

Cilium Agent synchronizes Kubernetes nodes information to the shared KVStore.

Buy Now
Question # 13

Review the Cilium Network Policy in the YAML file.

It was deployed in the ns-cca namespace on cluster1

Cluster Mesh CiliumNetworkPolicy exhibit

Which statement Is correct?

Options:

A.

This policy will allow traffic from a Pod named ship in ns-cca namespace in clusterl to a Pod named base in ns-cca namespace in cluster2.

B.

This policy will allow traffic from a Pod named ship in ns-cca namespace in clusterl to a Pod named base in default namespace in cluster2.

C.

This policy will deny traffic from a Pod named ship in ns-cca namespace in clusterl to a Pod named base in ns-cca namespace in cluster2.

D.

This policy will deny traffic from a Pod named ship in ns-cca namespace in clusterl to a Pod named base in default namespace in cluster2.

Buy Now
Exam Code: Cilium-Associate
Exam Name: Cilium Certified AssociateCCA
Last Update: Oct 3, 2026
Questions: 60
Cilium-Associate pdf

Cilium-Associate PDF

$21.25  $84.99
Cilium-Associate Engine

Cilium-Associate Testing Engine

$23.75  $94.99
Cilium-Associate PDF + Engine

Cilium-Associate PDF + Testing Engine

$33.75  $134.99