Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which command correctly creates a Role named 'pod-reader' that allows get, list, and watch on pods?

⚠ Common exam trap

Candidates often confuse the singular `--verb`/`--resource` flags with the plural `--verbs`/`--resources` or incorrectly use repeated `--verb` flags, leading to syntax errors or incorrect RBAC rule generation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl create role pod-reader --verb=get,list,watch --resource=pods

The `kubectl create role` command uses the `--verb` flag (singular) with comma-separated values and the `--resource` flag (singular) with the lowercase plural resource name 'pods'. This matches the Kubernetes API convention where resources are specified as lowercase plurals (e.g., 'pods', 'deployments') and verbs are comma-separated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl create role pod-reader --verb=get --verb=list --verb=watch --resource=pods

    Why it's wrong here

    The kubectl create role command expects a single --verb flag whose value is a comma-separated list, not repeated --verb flags. Because --verb is a plain string flag rather than an array flag, each additional instance overwrites the previous value, so only the last verb (watch) would actually be recorded if the command succeeds, or the command may error out with a flag parse issue. This means the Role would not grant get and list permissions, so it cannot define the intended combination of verbs.

  • ✗

    kubectl create role pod-reader --verb=get,list,watch --resource=Pod

    Why it's wrong here

    In Kubernetes RBAC, the resource field in a Role must be the lowercase plural name of the API resource, matching the resource path exposed by the API server (e.g., /api/v1/pods). Using the capitalized singular form 'Pod' does not correspond to any valid resource name, so kubectl create role will fail with a validation error indicating that the resource is invalid. The correct syntax always uses lowercase plural names for standard resources, such as pods, deployments, or services.

  • ✓

    kubectl create role pod-reader --verb=get,list,watch --resource=pods

    Why this is correct

    This is the correct syntax because it supplies all three verbs as a single comma-separated value for the --verb flag and specifies the resource using the standard lowercase plural name pods. The kubectl create role command uses this input to generate or directly create a Role object that grants get, list, and watch permissions on pods in the active namespace. This exactly matches the documented command line syntax for kubectl create role, making it the only valid option among the four.

  • ✗

    kubectl create role pod-reader --verbs=get,list,watch --resources=pods

    Why it's wrong here

    The flags --verbs and --resources do not exist on kubectl create role; the command uses the singular forms --verb and --resource. As a result, kubectl will return an 'unknown flag: --verbs' error and no Role will be created. Even if the flag names were accepted, the CLI is designed with a single --verb flag whose value can be a comma-separated list, so the plural flag names are fundamentally incompatible with the command's expected structure.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.