CKAD Practice Question: Application Environment, Configuration and Security
An administrator creates a Role and RoleBinding in the 'dev' namespace to allow a ServiceAccount 'sa-dev' to list Pods. Which YAML snippet correctly defines the Role?
⚠ Common exam trap
Watch out — candidates often confuse the core API group with the version string `v1` or mistakenly use `apps/v1` for Pods, and they may also confuse `list` with `get` or `create`, leading to incorrect verb selection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: {name: pod-reader, namespace: dev} rules: - apiGroups: [""] resources: ["pods"] verbs: ["list"]
It uses the empty string `""` for `apiGroups`, which represents the core API group where Pods reside, and specifies the `list` verb to allow listing Pods. This matches the requirement to allow the ServiceAccount 'sa-dev' to list Pods in the 'dev' namespace.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: {name: pod-reader, namespace: dev} rules: - apiGroups: [""] resources: ["pods"] verbs: ["create"]
Why it's wrong here
Using verbs: ["create"] grants permission to create pods, not to list them. The verb for reading a collection of resources is "list", so this Role would not satisfy the requirement to list pods. A correct Role must use verbs: ["list"] to allow the subject to retrieve pod objects from the dev namespace.
- ✗
apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: {name: pod-reader, namespace: dev} rules: - apiGroups: ["v1"] resources: ["pods"] verbs: ["list"]
Why it's wrong here
The apiGroups field for core Kubernetes resources like pods must be an empty string (""), not "v1". The string "v1" is not a valid API group; it is the version of the core API. Correctly specifying apiGroups: [""] targets the core group where pods reside, allowing the "list" verb to work as intended.
- ✗
apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: {name: pod-reader, namespace: dev} rules: - apiGroups: ["apps/v1"] resources: ["pods"] verbs: ["get"]
Why it's wrong here
Pods are part of the core API group, not the apps/v1 group. The apps/v1 group contains resources like Deployments, ReplicaSets, and StatefulSets, not pods. Additionally, the verb "get" only allows retrieving a single pod by name, not listing all pods in the namespace; the correct verb for listing is "list".
- ✓
apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: {name: pod-reader, namespace: dev} rules: - apiGroups: [""] resources: ["pods"] verbs: ["list"]
Why this is correct
This Role correctly uses apiGroups: [""] to target the core API group, resources: ["pods"] to specify the pod resource, and verbs: ["list"] to permit listing pods in the dev namespace. Because it is a Role (not a ClusterRole) bound to the dev namespace, it grants permissions only within that namespace, which matches the requirement.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.