Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A pod is running with the default service account. An administrator wants to prevent the pod from automatically mounting the service account token. Which field in the pod spec accomplishes this?

⚠ Common exam trap

Many exam-takers confuse `automountServiceAccountToken` with `serviceAccountName` or assume that setting an empty service account name removes the token, but only the explicit boolean field controls the mounting behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

automountServiceAccountToken: false

Setting `automountServiceAccountToken: false` in the pod spec explicitly prevents the automatic mounting of the service account token into the pod. By default, Kubernetes mounts a projected service account token into every pod at `/var/run/secrets/kubernetes.io/serviceaccount`; this field overrides that default behavior at the pod level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    serviceAccountName: ""

    Why it's wrong here

    Setting serviceAccountName to an empty string is effectively the same as omitting the field entirely. Kubernetes treats an empty serviceAccountName as a request to use the 'default' service account in the pod's namespace, so the kubelet will still mount the default service account token into the pod. This does not disable token mounting; it merely selects the default identity. To prevent the token from being mounted, you need to set automountServiceAccountToken: false.

  • ✓

    automountServiceAccountToken: false

    Why this is correct

    automountServiceAccountToken: false is the correct way to prevent automatic mounting of the service account token into a pod. This boolean field, defined in the PodSpec, tells the kubelet not to project the service account token at /var/run/secrets/kubernetes.io/serviceaccount. It can also be set on a ServiceAccount to apply the same behavior to all pods that use that account. This is a security best practice for workloads that do not need to interact with the Kubernetes API.

  • ✗

    serviceAccountToken: none

    Why it's wrong here

    serviceAccountToken: none is not a valid field in the Kubernetes PodSpec. The only fields related to service account configuration in a pod are serviceAccountName and automountServiceAccountToken. Attempting to set an unknown field like this would be rejected by the API server during validation, or at best ignored depending on the server's validation policy. There is no mechanism in Kubernetes to set a token value of 'none'; you must use automountServiceAccountToken: false.

  • ✗

    securityContext.readOnlyRootFilesystem: true

    Why it's wrong here

    securityContext.readOnlyRootFilesystem: true makes the container's root filesystem read-only, but it does not prevent the service account token from being mounted or accessed. The token is a volume mount that exists outside the root filesystem, and even if the filesystem is read-only, the token file remains readable at its mount path. Read-only root filesystems provide defense-in-depth but do not remove or hide the token. The only way to stop the token from being mounted is automountServiceAccountToken: false.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.