CKAD Practice Question: Application Environment, Configuration and Security
Which of the following correctly describes the purpose of a PodSecurityPolicy (PSP) in Kubernetes? (Note: PSP is deprecated in v1.21+ and removed in v1.25; Pod Security Admission is the replacement.)
⚠ Common exam trap
The trap here is that candidates may remember PSP as a namespace-scoped resource (Option C) because it is often associated with namespaces in documentation, but it is actually cluster-scoped, and the deprecation timeline (Option A) is a frequent distractor for those who haven't kept up with Kubernetes version changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PSP is deprecated; its replacement is Pod Security Admission (PSA)
PodSecurityPolicy (PSP) was indeed deprecated in Kubernetes v1.21 and removed in v1.25, with Pod Security Admission (PSA) as its official replacement. PSA uses built-in Pod Security Standards (baseline, restricted, privileged) enforced via admission controllers and labels, eliminating the need for a separate admission webhook or CRD-based policy object.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
PSP is deprecated; its replacement is Pod Security Admission (PSA)
Why this is correct
PodSecurityPolicy (PSP) was formally deprecated in Kubernetes v1.21 and entirely removed in v1.25, making it unavailable in current clusters. Its successor, Pod Security Admission (PSA), is a built-in admission controller that enforces the Pod Security Standards (baseline, restricted, privileged) at namespace granularity, addressing PSP's complexity and management overhead by providing a simpler, declarative approach without needing custom webhooks or separate RBAC.
- ✗
PSP is applied automatically to all pods in a cluster without configuration
Why it's wrong here
PSP never applied automatically; it required explicit activation of the PodSecurityPolicy admission controller in the API server and the creation of PSP objects along with RBAC rules granting Subjects (users, service accounts, or groups) permission to 'use' those policies. Without these configuration steps, pods were created without any PSP enforcement, so this option incorrectly suggests zero-config behavior.
- ✗
PSP is a namespace-scoped resource that defines default security for pods
Why it's wrong here
PSP is a cluster-scoped resource, not namespace-scoped. It was defined at the cluster level and could be bound to ServiceAccounts or users via RBAC, but the PSP object itself did not live within a namespace. This is in direct contrast to namespace-scoped resources like ResourceQuota or LimitRange, and it was a common source of misconfiguration because a single PSP could unintentionally affect pods across multiple namespaces if RBAC was overly broad.
- ✗
PSP cannot be used to control container security contexts
Why it's wrong here
PSP was specifically designed to control container security contexts. It could enforce settings such as privileged mode, host namespaces, allowed Linux capabilities, seccomp profiles, AppArmor, Sysctls, and filesystem group rules. A cluster admin could deny or require certain security context fields before pod admission, making this option factually incorrect and ignoring PSP's central purpose.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.