CKAD Practice Question: Application Environment, Configuration and Security
A pod is running with the default service account. An administrator wants to prevent the pod from automatically mounting the service account token. Which field in the pod spec accomplishes this?
⚠ Common exam trap
Many exam-takers confuse `automountServiceAccountToken` with `serviceAccountName` or assume that setting an empty service account name removes the token, but only the explicit boolean field controls the mounting behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
automountServiceAccountToken: false
Setting `automountServiceAccountToken: false` in the pod spec explicitly prevents the automatic mounting of the service account token into the pod. By default, Kubernetes mounts a projected service account token into every pod at `/var/run/secrets/kubernetes.io/serviceaccount`; this field overrides that default behavior at the pod level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
serviceAccountName: ""
Why it's wrong here
Setting serviceAccountName to an empty string is effectively the same as omitting the field entirely. Kubernetes treats an empty serviceAccountName as a request to use the 'default' service account in the pod's namespace, so the kubelet will still mount the default service account token into the pod. This does not disable token mounting; it merely selects the default identity. To prevent the token from being mounted, you need to set automountServiceAccountToken: false.
- ✓
automountServiceAccountToken: false
Why this is correct
automountServiceAccountToken: false is the correct way to prevent automatic mounting of the service account token into a pod. This boolean field, defined in the PodSpec, tells the kubelet not to project the service account token at /var/run/secrets/kubernetes.io/serviceaccount. It can also be set on a ServiceAccount to apply the same behavior to all pods that use that account. This is a security best practice for workloads that do not need to interact with the Kubernetes API.
- ✗
serviceAccountToken: none
Why it's wrong here
serviceAccountToken: none is not a valid field in the Kubernetes PodSpec. The only fields related to service account configuration in a pod are serviceAccountName and automountServiceAccountToken. Attempting to set an unknown field like this would be rejected by the API server during validation, or at best ignored depending on the server's validation policy. There is no mechanism in Kubernetes to set a token value of 'none'; you must use automountServiceAccountToken: false.
- ✗
securityContext.readOnlyRootFilesystem: true
Why it's wrong here
securityContext.readOnlyRootFilesystem: true makes the container's root filesystem read-only, but it does not prevent the service account token from being mounted or accessed. The token is a volume mount that exists outside the root filesystem, and even if the filesystem is read-only, the token file remains readable at its mount path. Read-only root filesystems provide defense-in-depth but do not remove or hide the token. The only way to stop the token from being mounted is automountServiceAccountToken: false.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.