CKAD Practice Question: Application Environment, Configuration and Security
Which of the following is a valid Pod Security Admission standard?
⚠ Common exam trap
Test-takers frequently confuse 'Default' with the 'Baseline' standard, or assume 'Secure' is a valid level, when in fact only Privileged, Baseline, and Restricted are defined in the Kubernetes documentation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restricted
The Pod Security Admission (PSA) standard defines three levels: Privileged, Baseline, and Restricted. Option C is correct because 'Restricted' is one of the three valid standards, designed to enforce the most restrictive pod security policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Privileged, Default
Why it's wrong here
The Pod Security Admission system defines exactly three policy levels: Privileged, Baseline, and Restricted. 'Privileged' is a legitimate standard, but 'Privileged, Default' is not a recognized policy; there is no combined 'Default' level within the PSA framework. A configuration referencing this pair would be rejected by the admission controller.
- ✗
Default
Why it's wrong here
'Default' is not one of the Pod Security Admission standards. PSA exposes only Privileged, Baseline, and Restricted as built-in policies; the term 'Default' appears in Kubernetes for things like the default namespace or default resource quotas, not as an admission policy label. Using 'Default' alone would be invalid.
- ✓
Restricted
Why this is correct
Restricted is a valid Pod Security Admission standard, representing the most stringent level. It enforces namespaces and pods to follow best practices such as disallowing privileged containers, dropping all capabilities, and setting a non-root user. This standard is often chosen for sensitive production workloads to minimize container escape risks.
- ✗
Secure
Why it's wrong here
'Secure' is a generic term and not a named Pod Security Admission standard. The three policy levels are Privileged, Baseline, and Restricted; no policy is called 'Secure'. Attempting to apply 'Secure' would be ignored or rejected because it does not map to a known PSA policy identifier.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.