CKAD Practice Question: Application Environment, Configuration and Security
A PodSecurityPolicy (PSP) has been replaced by Pod Security Admission. Which of the following commands applies a baseline pod security standard to the namespace 'dev'?
⚠ Common exam trap
Test-takers frequently confuse the three modes (enforce, warn, audit) and pick a mode that does not actually apply the standard, or they mistakenly select `privileged` thinking it is the baseline standard.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl label ns dev pod-security.kubernetes.io/enforce=baseline
Pod Security Admission uses labels on namespaces to enforce pod security standards. The label `pod-security.kubernetes.io/enforce=baseline` applies the baseline standard, which prevents known privilege escalations while allowing the default minimal pod configuration. This replaces the deprecated PodSecurityPolicy (PSP) with a built-in admission controller.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl label ns dev pod-security.kubernetes.io/warn=baseline
Why it's wrong here
The `warn=baseline` label instructs the Pod Security Admission controller to emit a warning message to the user when a pod violates the baseline standard, but it does not block the pod from being created. This mode is purely advisory; it surfaces policy violations in the client response (e.g., kubectl) and API server logs, yet the pod is still admitted. Because it lacks enforcement, it cannot satisfy the requirement to apply the baseline standard to the namespace.
- ✗
kubectl label ns dev pod-security.kubernetes.io/enforce=privileged
Why it's wrong here
Setting `enforce=privileged` configures the namespace to enforce the privileged Pod Security Standard, which is the most permissive level and effectively imposes no restrictions on pod security contexts, capabilities, or host access. This would allow pods that violate the baseline standard to be admitted without any rejection, meaning the baseline policy is not actually applied. The required behavior is to reject non-baseline-compliant pods, so this option actively undermines the goal by opting into a weaker standard.
- ✗
kubectl label ns dev pod-security.kubernetes.io/audit=baseline
Why it's wrong here
The `audit=baseline` label instructs the Pod Security Admission controller to record policy violations in the Kubernetes audit log while still allowing the pod to be created. This mode is intended for detection and monitoring rather than prevention; it captures events for review but does not block or warn the user. Therefore, it does not enforce the baseline standard and is insufficient when the explicit task is to enforce it via the `enforce` mode.
- ✓
kubectl label ns dev pod-security.kubernetes.io/enforce=baseline
Why this is correct
Setting `enforce=baseline` configures the Pod Security Admission controller to actively reject any pod in the `dev` namespace that violates the baseline Pod Security Standard. The baseline standard is the minimal set of restrictions designed to prevent privilege escalation and covers key security contexts like `allowPrivilegeEscalation` and `privileged`. This label is the correct way to enforce the baseline standard, as it makes the admission controller deny non-compliant pods at creation time.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.