Courseiva
System Hardening →hardMultiple Choice

CKS System Hardening Practice Question

A cluster administrator has applied a PodSecurityPolicy (PSP) to restrict privileged containers. After upgrading to Kubernetes 1.25, they notice that PSPs are no longer working. What is the MOST likely reason?

⚠ Common exam trap

Test-takers frequently think PSPs are merely deprecated or need a version update, but the CKS exam tests the specific knowledge that PSP was removed entirely in 1.25, and that NetworkPolicies serve a completely different purpose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PSP support was removed from Kubernetes in 1.25

PodSecurityPolicy (PSP) was deprecated in Kubernetes 1.21 and completely removed in Kubernetes 1.25, meaning the PSP admission controller and API resource no longer exist in that version. The cluster administrator's PSPs stopped working because the feature was removed entirely, not due to a configuration or versioning issue. The replacement is Pod Security Admission (PSA), which uses built-in admission controllers and Pod Security Standards.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The PSP API version needs to be updated to v1

    Why it's wrong here

    Updating the API version to v1 is impossible because PodSecurityPolicy never had a v1 API; the only implemented version was policy/v1beta1. More fundamentally, in Kubernetes 1.25 the entire PodSecurityPolicy API type and its associated admission controller were removed from the codebase, so no version—neither v1beta1 nor hypothetical v1—is available or functional. The correct action is to migrate to Pod Security Standards via the PodSecurity admission controller.

  • ✗

    PSPs were replaced by NetworkPolicies in 1.25

    Why it's wrong here

    This is incorrect because PodSecurityPolicy was not replaced by NetworkPolicy. NetworkPolicy governs layer 3/4 traffic between pods and is completely unrelated to security context, privilege escalation, or allowed volumes. In Kubernetes 1.25, PSPs were replaced by the PodSecurity admission controller, which enforces the Pod Security Standards (baseline, restricted, privileged). The two mechanisms address entirely different concerns—traffic filtering versus pod security configuration.

  • ✓

    PSP support was removed from Kubernetes in 1.25

    Why this is correct

    Correct: PodSecurityPolicy support was removed in Kubernetes 1.25. The PSP API (policy/v1beta1) was deprecated in v1.21 and removed entirely in v1.25, meaning any PSP manifest, even if syntactically valid, will be rejected by the API server and the admission plugin will no longer enforce anything. This is exactly why the administrator's PSP fails to take effect in a 1.25 cluster; the entire subsystem has been excised.

  • ✗

    The PSP was not applied to the correct namespace

    Why it's wrong here

    The namespace is not the issue because PodSecurityPolicy is a cluster-scoped resource, not namespaced. However, even if the PSP were correctly associated with the appropriate ServiceAccounts or users via RBAC, it would still have no effect in Kubernetes 1.25 because the PodSecurityPolicy API and admission controller have been completely removed. Thus, namespace misconfiguration is irrelevant; the removal of the resource type itself is the definitive cause of failure.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.