Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A PodSecurityPolicy (PSP) has been replaced by Pod Security Admission. Which of the following commands applies a baseline pod security standard to the namespace 'dev'?

⚠ Common exam trap

Test-takers frequently confuse the three modes (enforce, warn, audit) and pick a mode that does not actually apply the standard, or they mistakenly select `privileged` thinking it is the baseline standard.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl label ns dev pod-security.kubernetes.io/enforce=baseline

Pod Security Admission uses labels on namespaces to enforce pod security standards. The label `pod-security.kubernetes.io/enforce=baseline` applies the baseline standard, which prevents known privilege escalations while allowing the default minimal pod configuration. This replaces the deprecated PodSecurityPolicy (PSP) with a built-in admission controller.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl label ns dev pod-security.kubernetes.io/warn=baseline

    Why it's wrong here

    The `warn=baseline` label instructs the Pod Security Admission controller to emit a warning message to the user when a pod violates the baseline standard, but it does not block the pod from being created. This mode is purely advisory; it surfaces policy violations in the client response (e.g., kubectl) and API server logs, yet the pod is still admitted. Because it lacks enforcement, it cannot satisfy the requirement to apply the baseline standard to the namespace.

  • ✗

    kubectl label ns dev pod-security.kubernetes.io/enforce=privileged

    Why it's wrong here

    Setting `enforce=privileged` configures the namespace to enforce the privileged Pod Security Standard, which is the most permissive level and effectively imposes no restrictions on pod security contexts, capabilities, or host access. This would allow pods that violate the baseline standard to be admitted without any rejection, meaning the baseline policy is not actually applied. The required behavior is to reject non-baseline-compliant pods, so this option actively undermines the goal by opting into a weaker standard.

  • ✗

    kubectl label ns dev pod-security.kubernetes.io/audit=baseline

    Why it's wrong here

    The `audit=baseline` label instructs the Pod Security Admission controller to record policy violations in the Kubernetes audit log while still allowing the pod to be created. This mode is intended for detection and monitoring rather than prevention; it captures events for review but does not block or warn the user. Therefore, it does not enforce the baseline standard and is insufficient when the explicit task is to enforce it via the `enforce` mode.

  • ✓

    kubectl label ns dev pod-security.kubernetes.io/enforce=baseline

    Why this is correct

    Setting `enforce=baseline` configures the Pod Security Admission controller to actively reject any pod in the `dev` namespace that violates the baseline Pod Security Standard. The baseline standard is the minimal set of restrictions designed to prevent privilege escalation and covers key security contexts like `allowPrivilegeEscalation` and `privileged`. This label is the correct way to enforce the baseline standard, as it makes the admission controller deny non-compliant pods at creation time.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.