Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which of the following correctly describes the purpose of a PodSecurityPolicy (PSP) in Kubernetes? (Note: PSP is deprecated in v1.21+ and removed in v1.25; Pod Security Admission is the replacement.)

⚠ Common exam trap

The trap here is that candidates may remember PSP as a namespace-scoped resource (Option C) because it is often associated with namespaces in documentation, but it is actually cluster-scoped, and the deprecation timeline (Option A) is a frequent distractor for those who haven't kept up with Kubernetes version changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PSP is deprecated; its replacement is Pod Security Admission (PSA)

PodSecurityPolicy (PSP) was indeed deprecated in Kubernetes v1.21 and removed in v1.25, with Pod Security Admission (PSA) as its official replacement. PSA uses built-in Pod Security Standards (baseline, restricted, privileged) enforced via admission controllers and labels, eliminating the need for a separate admission webhook or CRD-based policy object.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    PSP is deprecated; its replacement is Pod Security Admission (PSA)

    Why this is correct

    PodSecurityPolicy (PSP) was formally deprecated in Kubernetes v1.21 and entirely removed in v1.25, making it unavailable in current clusters. Its successor, Pod Security Admission (PSA), is a built-in admission controller that enforces the Pod Security Standards (baseline, restricted, privileged) at namespace granularity, addressing PSP's complexity and management overhead by providing a simpler, declarative approach without needing custom webhooks or separate RBAC.

  • ✗

    PSP is applied automatically to all pods in a cluster without configuration

    Why it's wrong here

    PSP never applied automatically; it required explicit activation of the PodSecurityPolicy admission controller in the API server and the creation of PSP objects along with RBAC rules granting Subjects (users, service accounts, or groups) permission to 'use' those policies. Without these configuration steps, pods were created without any PSP enforcement, so this option incorrectly suggests zero-config behavior.

  • ✗

    PSP is a namespace-scoped resource that defines default security for pods

    Why it's wrong here

    PSP is a cluster-scoped resource, not namespace-scoped. It was defined at the cluster level and could be bound to ServiceAccounts or users via RBAC, but the PSP object itself did not live within a namespace. This is in direct contrast to namespace-scoped resources like ResourceQuota or LimitRange, and it was a common source of misconfiguration because a single PSP could unintentionally affect pods across multiple namespaces if RBAC was overly broad.

  • ✗

    PSP cannot be used to control container security contexts

    Why it's wrong here

    PSP was specifically designed to control container security contexts. It could enforce settings such as privileged mode, host namespaces, allowed Linux capabilities, seccomp profiles, AppArmor, Sysctls, and filesystem group rules. A cluster admin could deny or require certain security context fields before pod admission, making this option factually incorrect and ignoring PSP's central purpose.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.