Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

A cluster administrator wants to audit all pod creations and modifications using an admission webhook. Which resource type should be created to register the webhook?

⚠ Common exam trap

The CKS exam often tests the distinction between ValidatingWebhookConfiguration and MutatingWebhookConfiguration, trapping candidates who assume any admission webhook uses a generic 'WebhookConfiguration' or that auditing requires mutation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ValidatingWebhookConfiguration

A ValidatingWebhookConfiguration is the correct resource type to register an admission webhook that audits pod creations and modifications. This resource tells the API server which external HTTP callbacks to invoke during the admission process, specifically for validation (non-mutating) purposes. It defines the rules for matching API requests (e.g., operations like CREATE and UPDATE on pods) and the webhook endpoint that receives AdmissionReview requests.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ValidatingWebhookConfiguration

    Why this is correct

    A ValidatingWebhookConfiguration is the correct admissionregistration.k8s.io resource for registering a webhook that checks any matching API request. When a Pod creation is attempted, the API server serializes an AdmissionReview object and the webhook can return allowed:false to deny it. This enables custom, cluster-wide audit or validation policies without altering the submitted Pod spec.

  • ✗

    WebhookConfiguration

    Why it's wrong here

    WebhookConfiguration is not a kind defined by the Kubernetes API server. Admission webhooks are registered only through the two concrete types in the admissionregistration.k8s.io/v1 group: ValidatingWebhookConfiguration and MutatingWebhookConfiguration. A request to create a generic WebhookConfiguration would fail with an unknown object type, so it cannot be used to audit pod creations.

  • ✗

    MutatingWebhookConfiguration

    Why it's wrong here

    A MutatingWebhookConfiguration invokes webhooks during the mutating phase of admission, where the returned JSONPatch is applied to the object. This makes it suitable for injecting defaults, initContainers, or sidecars, not for a pass/fail audit decision. If used to 'audit' Pod creations, it would risk modifying every Pod, whereas the requirement is normally to evaluate the object and allow or deny it without changing the requested resource.

  • ✗

    AdmissionWebhook

    Why it's wrong here

    AdmissionWebhook is a colloquial term, not an actual API kind in any built-in Kubernetes group. The API server speaks about AdmissionReview from the admission.k8s.io/v1 group in the webhook payload, but there is no resource named AdmissionWebhook. Submitting such a resource would return a 'no matches for kind' error, so it cannot be part of the audit configuration.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.