Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which TWO of the following are required to create a Role and RoleBinding that grants read access to Pods in the 'development' namespace? (Choose two.)

⚠ Common exam trap

Many candidates confuse RoleBindings with ClusterRoleBindings, thinking a ClusterRoleBinding is needed for a Role, or they mistakenly believe a NetworkPolicy is part of RBAC, when it is a separate network security mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A RoleBinding that binds the Role to a subject (User or ServiceAccount)

A RoleBinding is the Kubernetes resource that binds a Role (which defines permissions) to a specific subject (User, Group, or ServiceAccount) within a namespace. Without a RoleBinding, the permissions defined in the Role are not granted to any identity, making it a required component for granting access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A NetworkPolicy that allows traffic to Pods

    Why it's wrong here

    A NetworkPolicy governs pod-to-pod traffic at the network layer (L3/L4) via selectors, not identity-based authorization. RBAC permissions are mediated by the kube-apiserver, whereas NetworkPolicy is enforced by the CNI plugin and never authenticates a User or ServiceAccount. Thus, without a Role and a binding, no API access is granted.

  • ✗

    A ClusterRole with the same rules

    Why it's wrong here

    While a ClusterRole could hold the same rules, RBAC for pods does not require cluster scope; a Role confined to the namespace is the minimal, standard choice. The question asks for required pieces, and a Role is sufficient because pods are namespaced resources. Using a ClusterRole would unnecessarily widen the security boundary and is not part of the minimal pair.

  • ✓

    A RoleBinding that binds the Role to a subject (User or ServiceAccount)

    Why this is correct

    A RoleBinding is the mandatory link that assigns the Role's permissions to a subject, such as a User, Group, or ServiceAccount, within a namespace. Without it, the Role exists in isolation and grants nothing. It also allows binding a ClusterRole, but here it binds the Role you created, completing the RBAC grant.

  • ✗

    A ClusterRoleBinding that binds the Role to a subject

    Why it's wrong here

    A ClusterRoleBinding cannot bind a namespaced Role at all — it only accepts a ClusterRole as its roleRef. Even if it could, it would grant the permissions cluster-wide, violating least privilege. A RoleBinding is the correct binding type for a Role that is meant to operate only in its namespace.

  • ✓

    A Role with apiGroups: [""], resources: ["pods"], verbs: ["get", "list", "watch"]

    Why this is correct

    This is the core Role object itself, correctly scoped to the namespace and specifying the API group, resources, and verbs. The apiGroups field must be present — "" denotes the core group, and the verbs "get", "list", "watch" are a common read-only set. Without this Role definition, there is no permission set to bind.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.