Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which of the following is a valid Pod Security Admission standard?

⚠ Common exam trap

Test-takers frequently confuse 'Default' with the 'Baseline' standard, or assume 'Secure' is a valid level, when in fact only Privileged, Baseline, and Restricted are defined in the Kubernetes documentation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restricted

The Pod Security Admission (PSA) standard defines three levels: Privileged, Baseline, and Restricted. Option C is correct because 'Restricted' is one of the three valid standards, designed to enforce the most restrictive pod security policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Privileged, Default

    Why it's wrong here

    The Pod Security Admission system defines exactly three policy levels: Privileged, Baseline, and Restricted. 'Privileged' is a legitimate standard, but 'Privileged, Default' is not a recognized policy; there is no combined 'Default' level within the PSA framework. A configuration referencing this pair would be rejected by the admission controller.

  • ✗

    Default

    Why it's wrong here

    'Default' is not one of the Pod Security Admission standards. PSA exposes only Privileged, Baseline, and Restricted as built-in policies; the term 'Default' appears in Kubernetes for things like the default namespace or default resource quotas, not as an admission policy label. Using 'Default' alone would be invalid.

  • ✓

    Restricted

    Why this is correct

    Restricted is a valid Pod Security Admission standard, representing the most stringent level. It enforces namespaces and pods to follow best practices such as disallowing privileged containers, dropping all capabilities, and setting a non-root user. This standard is often chosen for sensitive production workloads to minimize container escape risks.

  • ✗

    Secure

    Why it's wrong here

    'Secure' is a generic term and not a named Pod Security Admission standard. The three policy levels are Privileged, Baseline, and Restricted; no policy is called 'Secure'. Attempting to apply 'Secure' would be ignored or rejected because it does not map to a known PSA policy identifier.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.