Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A pod uses a ServiceAccount 'my-sa' but the pod's container needs to list pods in the namespace. Which RBAC resources are necessary?

⚠ Common exam trap

CNCF often tests the distinction between namespace-scoped and cluster-scoped RBAC resources, trapping candidates who assume that any 'list pods' operation requires a ClusterRole, when in fact a Role and RoleBinding are sufficient for a single namespace.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Role and RoleBinding

A Role and RoleBinding are necessary because the pod's ServiceAccount 'my-sa' needs permissions to list pods within a specific namespace. A Role defines the allowed API operations (e.g., 'list pods') scoped to a namespace, and a RoleBinding binds that Role to the ServiceAccount, granting those permissions within that namespace. This is the standard RBAC pattern for namespace-scoped access in Kubernetes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Role and RoleBinding

    Why this is correct

    This combination is correct because the pod's ServiceAccount needs permissions only within its own namespace. A Role defines namespace-scoped rules—such as get/list pods in the specified namespace—and the RoleBinding links that Role to the ServiceAccount as the subject. Since both the Role and the ServiceAccount exist in the same namespace, the RoleBinding can directly grant the pod's identity exactly the permissions it needs without exposing them cluster-wide.

  • ✗

    Role and ClusterRoleBinding

    Why it's wrong here

    A Role cannot be used with a ClusterRoleBinding; the roleRef of a ClusterRoleBinding must be a ClusterRole, not a namespaced Role. Even if this combination were valid, a ClusterRoleBinding grants the bound permissions in every namespace, far exceeding the namespace-scoped access the pod requires. The correct approach is a namespace-scoped RoleBinding, not a cluster-wide binding.

  • ✗

    ServiceAccount and RoleBinding only

    Why it's wrong here

    Creating only a ServiceAccount and a RoleBinding is incomplete because a RoleBinding's roleRef must reference an existing Role or ClusterRole that contains the permission rules. Without a Role (or ClusterRole) providing those rules, the RoleBinding has no permissions to bind and the ServiceAccount remains effectively unauthorized. The Role is the source of the allow rules; the RoleBinding merely applies them to the ServiceAccount subject.

  • ✗

    ClusterRole and ClusterRoleBinding

    Why it's wrong here

    ClusterRole and ClusterRoleBinding together grant the bound permissions across all namespaces, which is unnecessary and risky for a workload that should only interact with resources in its own namespace. Since the pod's ServiceAccount is namespace-scoped, using a cluster-wide binding violates least privilege and may allow access to secrets or other resources outside the intended scope. A namespace-local Role plus RoleBinding is the precise scoping mechanism for this case.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.