Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A developer creates a Role and RoleBinding in the namespace 'development' to grant list pods permission to a service account. Which manifest snippet correctly defines the Role?

⚠ Common exam trap

Test-takers frequently confuse the core API group with a named group like `"apps"` or use a wildcard `"*"` instead of the correct empty string `""`, leading to rules that either don't apply or are overly permissive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

rules: - apiGroups: [""] resources: ["pods"] verbs: ["list"]

Pods belong to the core API group, which is represented by an empty string `""` in the `apiGroups` field. The `list` verb is sufficient to list pods, and the `resources` field correctly specifies `pods`. This Role grants the service account permission to list pods in the `development` namespace.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    rules: - apiGroups: ["pods"] resources: ["pods"] verbs: ["get", "list"]

    Why it's wrong here

    Setting apiGroups to ["pods"] is incorrect because this field expects an API group name, not a resource type. Pods are part of the core API group, which is represented by the empty string "". Since no API group is literally named "pods", this rule will never match any real resource and effectively grants no permissions. The resource and verbs are correctly specified, but the invalid group makes the entire rule useless.

  • ✗

    rules: - apiGroups: ["apps"] resources: ["pods"] verbs: ["list"]

    Why it's wrong here

    Pods do not belong to the apps API group; that group contains resources such as Deployments, ReplicaSets, and StatefulSets. The core resources like pods are in the legacy core group, which is specified with an empty string "". Using "apps" scopes the rule to the wrong API group, so it would have no effect on Pod resources. Always use "" for core resources unless the resource is explicitly in a named group.

  • ✓

    rules: - apiGroups: [""] resources: ["pods"] verbs: ["list"]

    Why this is correct

    This rule is correct because the apiGroups field uses an empty string "", which is the proper way to reference the Kubernetes core API group where pods live. The resource "pods" and verb "list" are valid, and because this is a Role (not a ClusterRole), it grants the ability to list pods only within the namespace where the Role is bound. This minimal, precise scope aligns with RBAC best practices.

  • ✗

    rules: - apiGroups: ["*"] resources: ["pods"] verbs: ["list"]

    Why it's wrong here

    Using apiGroups: ["*"] is not the correct way to target the core API group. The asterisk wildcard matches all API groups, which is broader than needed and could unintentionally grant permissions to resources in other groups that happen to share the same name or future groups. For core resources like pods, the conventional and precise notation is the empty string "" in the apiGroups field. Least-privilege principles require specifying the exact group rather than relying on a wildcard.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.