CKS System Hardening Practice Question
A cluster administrator has applied a PodSecurityPolicy (PSP) to restrict privileged containers. After upgrading to Kubernetes 1.25, they notice that PSPs are no longer working. What is the MOST likely reason?
⚠ Common exam trap
Test-takers frequently think PSPs are merely deprecated or need a version update, but the CKS exam tests the specific knowledge that PSP was removed entirely in 1.25, and that NetworkPolicies serve a completely different purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PSP support was removed from Kubernetes in 1.25
PodSecurityPolicy (PSP) was deprecated in Kubernetes 1.21 and completely removed in Kubernetes 1.25, meaning the PSP admission controller and API resource no longer exist in that version. The cluster administrator's PSPs stopped working because the feature was removed entirely, not due to a configuration or versioning issue. The replacement is Pod Security Admission (PSA), which uses built-in admission controllers and Pod Security Standards.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The PSP API version needs to be updated to v1
Why it's wrong here
Updating the API version to v1 is impossible because PodSecurityPolicy never had a v1 API; the only implemented version was policy/v1beta1. More fundamentally, in Kubernetes 1.25 the entire PodSecurityPolicy API type and its associated admission controller were removed from the codebase, so no version—neither v1beta1 nor hypothetical v1—is available or functional. The correct action is to migrate to Pod Security Standards via the PodSecurity admission controller.
- ✗
PSPs were replaced by NetworkPolicies in 1.25
Why it's wrong here
This is incorrect because PodSecurityPolicy was not replaced by NetworkPolicy. NetworkPolicy governs layer 3/4 traffic between pods and is completely unrelated to security context, privilege escalation, or allowed volumes. In Kubernetes 1.25, PSPs were replaced by the PodSecurity admission controller, which enforces the Pod Security Standards (baseline, restricted, privileged). The two mechanisms address entirely different concerns—traffic filtering versus pod security configuration.
- ✓
PSP support was removed from Kubernetes in 1.25
Why this is correct
Correct: PodSecurityPolicy support was removed in Kubernetes 1.25. The PSP API (policy/v1beta1) was deprecated in v1.21 and removed entirely in v1.25, meaning any PSP manifest, even if syntactically valid, will be rejected by the API server and the admission plugin will no longer enforce anything. This is exactly why the administrator's PSP fails to take effect in a 1.25 cluster; the entire subsystem has been excised.
- ✗
The PSP was not applied to the correct namespace
Why it's wrong here
The namespace is not the issue because PodSecurityPolicy is a cluster-scoped resource, not namespaced. However, even if the PSP were correctly associated with the appropriate ServiceAccounts or users via RBAC, it would still have no effect in Kubernetes 1.25 because the PodSecurityPolicy API and admission controller have been completely removed. Thus, namespace misconfiguration is irrelevant; the removal of the resource type itself is the definitive cause of failure.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Policy Enforcement and Admission Controllers
Key term
OPA Gatekeeper
OPA Gatekeeper is a Kubernetes admission controller that enforces custom security and compliance policies on resources before they are created or updated in a cluster.
Key term
Pod Security Admission
Pod Security Admission is a Kubernetes feature that enforces security standards on pods at creation time to prevent running containers with dangerous privileges.
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.