CKAD Practice Question: Application Environment, Configuration and Security
A pod named 'test-pod' in namespace 'test' has a service account 'my-sa' attached. The service account has a RoleBinding to a Role that allows get/list pods. However, the pod cannot list pods. What is the most likely issue?
⚠ Common exam trap
CNCF often tests the namespace-scoping of RoleBindings versus ClusterRoleBindings, tricking candidates into thinking a RoleBinding in any namespace can grant permissions to a pod in another namespace.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The RoleBinding is in a different namespace than the pod
RoleBindings in Kubernetes are namespace-scoped and can only grant permissions within the namespace where they are created. If the RoleBinding is in a different namespace than the pod, the service account 'my-sa' will not have the get/list pods permissions in the pod's namespace, causing the pod to fail when trying to list pods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The pod is using the default service account instead of 'my-sa'
Why it's wrong here
A pod uses whichever service account is named in its spec. Since the pod manifest explicitly sets serviceAccountName: my-sa, the default 'default' SA is never used; Kubernetes projects that SA's token into the pod. To confirm, inspect `spec.serviceAccountName` in the pod's YAML. Thus, this cannot explain RBAC failure, because the intended SA is active.
- ✓
The RoleBinding is in a different namespace than the pod
Why this is correct
RoleBindings are namespace-scoped resources: they bind a Role to a service account only within the namespace where the RoleBinding is created. If the RoleBinding resides in, say, 'kube-system' instead of 'test', the SA 'my-sa' in 'test' has no permissions, and the pod cannot list pods. The RoleBinding must be in the same namespace as the pod and its service account to take effect.
- ✗
RoleBindings cannot grant access to list pods
Why it's wrong here
RoleBindings can contain any rule that a Role defines, including the verb 'list' on the 'pods' resource. The RBAC API treats list, get, watch, create, update, patch, delete as ordinary verbs. A RoleBinding simply links the Role to a subject; it does not filter or reject verbs. So there is no technical limitation preventing a RoleBinding from granting list pod access.
- ✗
The pod has automountServiceAccountToken set to false
Why it's wrong here
Kubernetes automatically mounts a service account token unless the pod sets automountServiceAccountToken: false. By default, this field is true, so the token is present. Setting it to false would prevent the pod's client from authenticating to the API, yielding authentication errors rather than RBAC permission denied errors. This is a misdiagnosis because the symptom described likely involves an authorization decision, which requires a valid token anyway.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.