Courseiva
KCSA
Kubernetes Security FundamentalseasyMultiple ChoiceObjective-mapped

KCSA Kubernetes Security Fundamentals Practice Question

An administrator wishes to inspect which admission controllers are currently enabled in a running Kubernetes cluster. Where is this typically configured in a stacked control plane?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

In the kube-apiserver static pod manifest file under '/etc/kubernetes/manifests/kube-apiserver.yaml'.

Admission controllers are configured via the '--enable-admission-plugins' flag on the kube-apiserver static pod manifest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • In the kube-apiserver static pod manifest file under '/etc/kubernetes/manifests/kube-apiserver.yaml'.

    Why this is correct

    The API server configuration file defines active admission plugins.

  • In the CoreDNS deployment spec.

    Why it's wrong here

    CoreDNS handles cluster internal name resolution, unrelated to admission control.

  • In the kubelet configuration file on each worker node.

    Why it's wrong here

    Kubelet manages node-level container lifecycles, not cluster-wide admission control.

  • In the cluster-wide ConfigMap named 'kube-system/cluster-admission'.

    Why it's wrong here

    Admission plugins for the core API server are set via command-line flags, not a ConfigMap.

About these practice questions

Courseiva writes every KCSA question from scratch — 320 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official CNCF / Linux Foundation exam blueprint

This KCSA practice question is part of Courseiva's free CNCF / Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCSA exam.