CKS Minimize Microservice Vulnerabilities Practice Question
A cluster administrator has configured EncryptionConfiguration to encrypt secrets at rest using a local key. After applying the configuration, the administrator creates a new secret. How can they verify that the secret is encrypted at rest?
⚠ Common exam trap
Watch out — candidates often assume Kubernetes CLI commands like kubectl get or describe can reveal encryption status, when in fact the API server transparently decrypts data on retrieval, so you must bypass the API server and inspect the storage backend directly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use etcdctl to read the secret directly from etcd and verify it is encrypted.
Encryption at rest is applied at the etcd storage layer, not at the Kubernetes API level. To verify that a secret is actually encrypted when stored, you must read it directly from etcd using etcdctl (with the appropriate endpoint and certificate flags). If the encryption configuration is working, the secret data will appear as base64-encoded ciphertext (e.g., starting with 'k8s:enc:aescbc:...') rather than plaintext base64 of the original secret data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run kubectl get secret -o yaml and check for an encryption annotation.
Why it's wrong here
The kubectl get secret -o yaml command retrieves the secret through the API server, which transparently decrypts the data before returning it, so you see plaintext (base64-encoded but unencrypted) values. Kubernetes does not add an annotation to secret objects indicating whether encryption at rest is enabled; annotations are arbitrary metadata and would not reflect storage-layer encryption. Additionally, the API server decrypts the data in memory, so there is no encrypted representation in the YAML to inspect.
- ✗
Use kubectl describe secret and look for 'Encrypted: true'.
Why it's wrong here
The kubectl describe secret command displays secret metadata, type, and data field names (with sizes), but it never includes an 'Encrypted' field or any indication of encryption status because the Kubernetes API does not expose such information. Encryption at rest is a storage-layer feature of the etcd backend, completely invisible to API clients. The output format is fixed by the API server and will not show a boolean flag like 'Encrypted: true'.
- ✗
Check the apiserver logs for encryption status messages.
Why it's wrong here
API server logs may record configuration details at startup, such as the chosen encryption provider or errors loading the EncryptionConfiguration file, but they do not log per-secret encryption status for read or write operations. Each secret is encrypted and decrypted in the storage layer on the fly, and these operations are not audited by default nor written to the event log. Therefore, examining logs would not give you any definitive information about whether a specific secret is encrypted at rest.
- ✓
Use etcdctl to read the secret directly from etcd and verify it is encrypted.
Why this is correct
Reading the secret directly from etcd with etcdctl bypasses the API server's decryption layer, giving you the raw bytes as stored. When encryption at rest is enabled, the stored value begins with a 'k8s:enc:' prefix followed by the encryption provider name (e.g., 'aescbc'), and the payload is ciphertext. This is the only reliable method to verify that a secret is encrypted on disk, because it shows the actual storage format without any API server processing.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.