CKA Practice Question: Cluster Architecture, Installation and Configuration
You need to create a RoleBinding that grants a user access to read Pods in the 'dev' namespace. Which YAML manifest is correct?
⚠ Common exam trap
CNCF often tests the distinction between RoleBinding and ClusterRoleBinding, and candidates mistakenly choose a ClusterRoleBinding when namespace-scoped access is required, or forget to include the namespace in the RoleBinding metadata.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: namespace: dev ... subjects: - kind: User name: dev-user roleRef: kind: Role name: pod-reader
It defines a RoleBinding in the 'dev' namespace that binds a User named 'dev-user' to a Role named 'pod-reader'. This grants the user read access to Pods within that specific namespace, which is exactly what the question requires. RoleBindings are namespace-scoped and must specify the target namespace in metadata.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: namespace: dev ... subjects: - kind: ServiceAccount name: dev-user roleRef: kind: Role name: pod-reader
Why it's wrong here
This manifest declares a RoleBinding in the dev namespace, but the subject is a ServiceAccount named dev-user. ServiceAccounts are identities for Pods and automated workloads, not for human users, so the bind would grant the pod-reader Role to the service account, leaving the actual user without any permissions. To grant a human user access, the subject kind must be 'User' (or 'Group' if referring to a group), and the service account would need to exist and be referenced with its own namespace. Therefore, this option fails because it targets the wrong principal type.
- ✗
apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding ... subjects: - kind: User name: dev-user roleRef: kind: ClusterRole name: pod-reader
Why it's wrong here
Using ClusterRole in a RoleBinding is valid only if the ClusterRole is scoped to the namespace, but the question asks for a RoleBinding. However, the RoleBinding itself is correct for namespace scoping, but the roleRef uses ClusterRole, which may not be restricted to the namespace. The correct approach is to use a Role.
- ✗
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding ... subjects: - kind: User name: dev-user roleRef: kind: ClusterRole name: pod-reader
Why it's wrong here
This option uses a ClusterRoleBinding, which is a cluster-scoped resource that grants permissions across all namespaces (or on cluster-level resources). The requirement is to grant access only in the 'dev' namespace, so the binding must be a RoleBinding, which is namespace-scoped. Even though the ClusterRole 'pod-reader' might exist, binding it via ClusterRoleBinding makes the user effective cluster-wide, violating the namespace isolation the question demands. The correct construct is a RoleBinding in the 'dev' namespace referencing a Role or a ClusterRole (the latter scoped to the namespace), but not a ClusterRoleBinding.
- ✓
apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: namespace: dev ... subjects: - kind: User name: dev-user roleRef: kind: Role name: pod-reader
Why this is correct
This is the correct answer. The RoleBinding is defined with 'namespace: dev', which confines the authorization to the dev namespace. The subject uses 'kind: User' and 'name: dev-user', correctly identifying the human user who needs access. The roleRef points to a Role named 'pod-reader' in the same namespace, which is the appropriate binding structure for granting namespace-scoped permissions to a named user. This combination satisfies the requirement of granting the user access to pod-reader only in the dev namespace.
About these practice questions
One of 726 original CKA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.