Skip to content

Policy Management Questions

Practice questions for Policy Management topic in Kyverno Certified Associate. 20 questions covering this domain.

20 questions7 easy11 medium2 hard
Q1
medium

Which Kyverno controller handles background scanning that records validation and `verifyImages` results for existing resources?

Q2
medium

A platform team wants to use `PolicyException` resources in a cluster where they are currently unavailable. What must it configure?

Q3
medium

When Kyverno is installed with Helm and metrics services are created, which port is exposed for metrics by default?

Q4
hard

A namespaced resource would normally fail a validate rule, but a matching PolicyException applies during background processing. How should that outcom...

Q5
easy

What does a `skip` result in a PolicyReport mean?

Q6
easy

A PolicyReport entry shows a result of `warn`. What does this indicate?

Q7
medium

A PolicyException resource is created but it is not being applied to matching resources. After checking the policy, a team discovers that `features.po...

Q8
medium

Which Prometheus metric tracks the total number of policy rule evaluation results (pass, fail, warn, error, skip) in Kyverno?

Q9
easy

What is the default port on which Kyverno exposes its Prometheus metrics?

Q10
hard

A PolicyException is matched against a resource during background scanning. What result will appear in the PolicyReport for that resource-rule combina...

Q11
easy

A PolicyReport entry shows `skip`. What does that result mean?

Q12
medium

A team wants one policy to stop generating any reports at all, including ephemeral and permanent reports. What should it add to that policy?

Q13
easy

A large cluster wants to store only failing results in reports to reduce report volume and ETCD pressure. Which flag supports that tuning?

Q14
medium

A platform team wants Kyverno to publish permanent reports in the `openreports.io` API group instead of the default report group. Which configuration ...

Q15
medium

By default, how often does Kyverno perform background scanning for reporting existing-resource policy results?

Q16
easy

Which Kyverno metric exposes the running Kyverno version through labels on a constant gauge?

Q17
easy

Which Kyverno Prometheus metric counts policy rule execution results such as pass and fail?

Q18
medium

Which statement correctly describes PolicyReport scope in Kyverno?

Q19
medium

A platform team asks why an Enforce-mode policy that blocked a bad admission request does not show a historical fail entry for that blocked object in ...

Q20
medium

What must be enabled if Kyverno should generate reports for Kubernetes ValidatingAdmissionPolicies and their bindings?

Sign in to see all 20 questions

Create a free account to browse all questions — completely free during our launch phase.