Which affirmation is true about eBPF host-routing?
Correct Answer: C
Technical explanation C accurately describes eBPF host-routing. In a conventional datapath, packets may traverse substantial portions of the host networking stack and its iptables hooks even when Cilium performs routing decisions with eBPF. eBPF host-routing takes a more direct datapath, bypassing iptables and the upper host stack while providing a faster transition between the host and pod network namespaces. This reduces processing and context-switching overhead and can improve throughput and latency. Option A describes load-balancing behavior rather than host routing. Backend distribution is implemented through Cilium's service load-balancer maps and algorithms. Host routing can improve the path used by resulting packets, but it does not itself guarantee even backend selection. Option B is the description of BIG TCP. BIG TCP increases the size of internal GSO and GRO packets to reduce stack traversal. Although BIG TCP requires eBPF host-routing in supported Cilium configurations, the two are distinct features. Option D is overly specific and does not define the feature. Host routing optimizes compatible pod traffic generally, subject to kernel, kube-proxy-replacement, masquerading, netfilter, encryption, and integration constraints. Official references Cilium eBPF Host-Routing Study Guide topic: eBPF host-routing, host-stack bypass, veth traversal, and performance.
Question 7
Which Cilium configuration is recommended to help identify the correct configuration of network policies without interrupting workload communications?
Correct Answer: D
Technical explanation Policy Audit Mode allows administrators to evaluate the consequences of network policies before enforcing their deny decisions. Traffic that would ordinarily be rejected remains permitted, while Cilium records an audit verdict. These verdicts can be examined with Cilium monitoring tools and used to identify legitimate communications that are missing from the proposed policies. This is especially valuable when introducing host policies or default-deny controls into an existing environment. An incomplete policy might otherwise block access to the Kubernetes API, node-management interfaces, DNS, monitoring systems, or other operational dependencies. The recommended workflow is to enable audit mode, observe traffic and policy verdicts, adjust the rules, confirm that all required communications receive allow verdicts, and then disable audit mode to begin enforcement. DNS enforcement mode and HTTP audit mode are not the general Cilium configuration requested. "Policy enforcement mode" describes whether policies are normally enforced, but it does not provide the non- disruptive learning behavior in the question. Audit mode should be treated as a temporary validation mechanism because it does not actually block disallowed traffic and does not persist across every agent-restart scenario. Official references Cilium Policy Audit Mode Study Guide topic: Policy validation, audit verdicts, and safe policy rollout.
Question 8
You want to consult the current Cilium configuration using the Cilium CLI. Which command should you use?
Correct Answer: D
Technical explanation cilium config view is the Cilium CLI command intended to display the current configuration. It reads the configuration associated with the selected Kubernetes context, Cilium namespace, and Helm release and presents the relevant settings for inspection. This makes D the direct answer. cilium status performs a different function. It reports the health and readiness of Cilium components such as the agent DaemonSet, operator, Envoy, Hubble Relay, and Cluster Mesh. Although status output may reveal a small amount of deployment information, it is not a complete configuration-viewing command. cilium sysdump collects a comprehensive troubleshooting archive containing Kubernetes resources, component logs, command output, configuration data, and other diagnostic evidence. It is appropriate when preparing a support bundle, but it is unnecessarily broad for simply consulting the current configuration. cilium context deals with Kubernetes context selection or inspection rather than displaying Cilium's configured values. The Cilium CLI organizes configuration operations under the cilium config command group. Related subcommands include set , delete , and view . Because the requested action is read-only inspection of the existing settings, view is the appropriate subcommand. Official references Cilium CLI `config view` . Study Guide topic: Installation and Configuration.
Question 9
What does this Egress Gateway policy achieve? Cilium Egress Gateway policy exhibit
Correct Answer: A
Cilium's official documentation confirms that a CiliumEgressGatewayPolicy selects traffic originating from matching pods , routes traffic destined for the configured destinationCIDRs through the selected egress gateway node, and SNATs that traffic using the configured egressIP.
Question 10
This an Ingress configuration. What is the equivalent Gateway API configuration? Question 19 source Ingress A) Question 19 option A B) Question 19 option B C) Question 19 option C D) Question 19 option D
Correct Answer: B
Technical explanation Option B correctly represents the Ingress as a Gateway and an attached HTTPRoute . The Gateway is named cilium , uses gatewayClassName: cilium , and exposes an HTTP listener on port 80. The HTTPRoute uses parentRefs with the same Gateway name, cilium , so the route attaches to the declared listener. Its two rules preserve the original routing behavior: /details with PathPrefix targets the details Service on port 9080, while / with PathPrefix targets productpage on port 9080. Option A declares a Gateway named cilium but attaches its route to nginx-gateway . Because the parent reference does not identify the displayed Gateway, it is not equivalent. Options C and D use kind: Route ; the correct resource kind for HTTP path routing is HTTPRoute . They also contain malformed or altered backend and matching fields. Option D changes the details backend name, while option C contains incorrect route structure and path content. Cilium's official migration example uses the same conversion pattern: the Ingress class becomes the Gateway' s class, paths move into HTTPRoute.rules , and the route identifies its Gateway through parentRefs . The supplied key incorrectly identifies A. The verified answer is B. Official references HTTP Migration Example . Study Guide topic: Service Mesh.