CKAD Practice Question: Application Environment, Configuration and Security
An administrator wants to enforce that all Pods in a namespace run with a read-only root filesystem. Which admission controller should be configured?
⚠ Common exam trap
A common mix-up: candidates confuse admission controllers that manage resource quotas (LimitRange, ResourceQuota) with those that enforce security policies, or mistakenly think a webhook is required when a built-in controller like PSA already provides the needed enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pod Security Admission (PSA)
Pod Security Admission (PSA) is the correct choice because it enforces Pod Security Standards (PSS) at the namespace level, including the `Restricted` profile which mandates a read-only root filesystem (`readOnlyRootFilesystem: true`). PSA is a built-in admission controller that evaluates pod specifications against predefined security policies and rejects pods that violate them, making it the appropriate tool for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
LimitRange
Why it's wrong here
A LimitRange is a namespaced policy object that constrains per-pod or per-container resource requests and limits for CPU, memory, and storage. It operates purely on resource quantities during admission and cannot inspect or enforce security settings such as readOnlyRootFilesystem. Thus, while it can set defaults for resource usage, it has no mechanism to mandate a pod's security context.
- ✗
ResourceQuota
Why it's wrong here
A ResourceQuota enforces aggregate resource consumption ceilings across all pods and services in a namespace, limiting total CPU, memory, and object counts. It is a counting and quantity-based admission control, not a policy engine for pod security attributes. Therefore, it cannot condition a pod's creation on having a read-only root filesystem, as it lacks access to the securityContext fields.
- ✗
MutatingAdmissionWebhook
Why it's wrong here
A MutatingAdmissionWebhook can intercept pod creation requests and modify their securityContext, so in theory it could inject readOnlyRootFilesystem: true to satisfy an administrator's requirement. However, this requires writing, deploying, and maintaining a custom webhook server with TLS and failure rules, creating operational complexity. Kubernetes instead provides Pod Security Admission as a standard built-in controller that directly enforces the restricted profile, making it the preferred and simpler solution.
- ✓
Pod Security Admission (PSA)
Why this is correct
Pod Security Admission (PSA) is a built-in admission controller that enforces the Pod Security Standards, which define privileged, baseline, and restricted security profiles. The restricted profile explicitly requires readOnlyRootFilesystem: true, along with preventing privileged containers, host namespaces, and other high-risk capabilities. By labeling a namespace with the enforce level and restricted version, an administrator guarantees that every pod meets these mandatory security context requirements.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.