CKAD Practice Question: Application Environment, Configuration and Security
Which annotation is used to enforce Pod Security Admission at the 'restricted' level on a namespace?
⚠ Common exam trap
A common mix-up: candidates confuse the `enforce` mode (which blocks non-compliant pods) with the `warn` or `audit` modes (which only notify or log), and may also mistakenly choose `baseline` thinking it is the highest security level, when in fact `restricted` is the most stringent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
pod-security.kubernetes.io/enforce: restricted
The `pod-security.kubernetes.io/enforce` annotation enforces Pod Security Standards (PSS) at the namespace level, and setting it to `restricted` blocks any pod that violates the most stringent set of security controls (e.g., running as root, privileged containers). This is the only annotation that actively prevents non-compliant pods from being created, rather than just warning or logging violations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
pod-security.kubernetes.io/enforce: restricted
Why this is correct
The `pod-security.kubernetes.io/enforce: restricted` annotation is the correct mechanism to actively enforce the strictest Pod Security Standard. When a namespace carries this label, the Pod Security Admission controller rejects any pod that fails the restricted policy, preventing its creation. This is the only option that both blocks violating resources and mandates the most hardened security posture, covering privileged containers, host namespaces, and other high-risk settings.
- ✗
pod-security.kubernetes.io/warn: restricted
Why it's wrong here
The `pod-security.kubernetes.io/warn: restricted` annotation does not enforce compliance; it only instructs the Pod Security Admission controller to emit a warning to the user (and the API server audit log) when a pod violates the restricted standard. Because it lacks the `enforce` action, the pod is still admitted and scheduled, meaning misconfigurations go live despite the visible warning. This is useful for user-facing feedback during migration, not for actual security guarantees.
- ✗
pod-security.kubernetes.io/enforce: baseline
Why it's wrong here
Using `pod-security.kubernetes.io/enforce: baseline` enforces the baseline Pod Security Standard, not the restricted one. The baseline profile allows several privileged capabilities that restricted forbids, such as CAP_SYS_ADMIN, certain host paths, and non-root filesystem constraints, making it a lower security bar. While it will reject many unsafe pods, it fails to block others that restricted would catch—so it is not the correct annotation for enforcing the strongest policy.
- ✗
pod-security.kubernetes.io/audit: restricted
Why it's wrong here
The `pod-security.kubernetes.io/audit: restricted` annotation activates the audit level of Pod Security Admission, which records violations of the restricted standard in the API server audit logs. This action never blocks pod creation or updates; it only adds audit events for compliance monitoring or post-hoc analysis. It is therefore a non-enforcement mechanism, and relying on it alone would leave your cluster vulnerable to restricted-level violations.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.