CKAD Practice Question: Application Environment, Configuration and Security
A pod uses a ServiceAccount 'my-sa' but the pod's container needs to list pods in the namespace. Which RBAC resources are necessary?
⚠ Common exam trap
CNCF often tests the distinction between namespace-scoped and cluster-scoped RBAC resources, trapping candidates who assume that any 'list pods' operation requires a ClusterRole, when in fact a Role and RoleBinding are sufficient for a single namespace.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role and RoleBinding
A Role and RoleBinding are necessary because the pod's ServiceAccount 'my-sa' needs permissions to list pods within a specific namespace. A Role defines the allowed API operations (e.g., 'list pods') scoped to a namespace, and a RoleBinding binds that Role to the ServiceAccount, granting those permissions within that namespace. This is the standard RBAC pattern for namespace-scoped access in Kubernetes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Role and RoleBinding
Why this is correct
This combination is correct because the pod's ServiceAccount needs permissions only within its own namespace. A Role defines namespace-scoped rules—such as get/list pods in the specified namespace—and the RoleBinding links that Role to the ServiceAccount as the subject. Since both the Role and the ServiceAccount exist in the same namespace, the RoleBinding can directly grant the pod's identity exactly the permissions it needs without exposing them cluster-wide.
- ✗
Role and ClusterRoleBinding
Why it's wrong here
A Role cannot be used with a ClusterRoleBinding; the roleRef of a ClusterRoleBinding must be a ClusterRole, not a namespaced Role. Even if this combination were valid, a ClusterRoleBinding grants the bound permissions in every namespace, far exceeding the namespace-scoped access the pod requires. The correct approach is a namespace-scoped RoleBinding, not a cluster-wide binding.
- ✗
ServiceAccount and RoleBinding only
Why it's wrong here
Creating only a ServiceAccount and a RoleBinding is incomplete because a RoleBinding's roleRef must reference an existing Role or ClusterRole that contains the permission rules. Without a Role (or ClusterRole) providing those rules, the RoleBinding has no permissions to bind and the ServiceAccount remains effectively unauthorized. The Role is the source of the allow rules; the RoleBinding merely applies them to the ServiceAccount subject.
- ✗
ClusterRole and ClusterRoleBinding
Why it's wrong here
ClusterRole and ClusterRoleBinding together grant the bound permissions across all namespaces, which is unnecessary and risky for a workload that should only interact with resources in its own namespace. Since the pod's ServiceAccount is namespace-scoped, using a cluster-wide binding violates least privilege and may allow access to secrets or other resources outside the intended scope. A namespace-local Role plus RoleBinding is the precise scoping mechanism for this case.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.