CKS Minimize Microservice Vulnerabilities Practice Question
A cluster administrator wants to audit all pod creations and modifications using an admission webhook. Which resource type should be created to register the webhook?
⚠ Common exam trap
The CKS exam often tests the distinction between ValidatingWebhookConfiguration and MutatingWebhookConfiguration, trapping candidates who assume any admission webhook uses a generic 'WebhookConfiguration' or that auditing requires mutation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ValidatingWebhookConfiguration
A ValidatingWebhookConfiguration is the correct resource type to register an admission webhook that audits pod creations and modifications. This resource tells the API server which external HTTP callbacks to invoke during the admission process, specifically for validation (non-mutating) purposes. It defines the rules for matching API requests (e.g., operations like CREATE and UPDATE on pods) and the webhook endpoint that receives AdmissionReview requests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ValidatingWebhookConfiguration
Why this is correct
A ValidatingWebhookConfiguration is the correct admissionregistration.k8s.io resource for registering a webhook that checks any matching API request. When a Pod creation is attempted, the API server serializes an AdmissionReview object and the webhook can return allowed:false to deny it. This enables custom, cluster-wide audit or validation policies without altering the submitted Pod spec.
- ✗
WebhookConfiguration
Why it's wrong here
WebhookConfiguration is not a kind defined by the Kubernetes API server. Admission webhooks are registered only through the two concrete types in the admissionregistration.k8s.io/v1 group: ValidatingWebhookConfiguration and MutatingWebhookConfiguration. A request to create a generic WebhookConfiguration would fail with an unknown object type, so it cannot be used to audit pod creations.
- ✗
MutatingWebhookConfiguration
Why it's wrong here
A MutatingWebhookConfiguration invokes webhooks during the mutating phase of admission, where the returned JSONPatch is applied to the object. This makes it suitable for injecting defaults, initContainers, or sidecars, not for a pass/fail audit decision. If used to 'audit' Pod creations, it would risk modifying every Pod, whereas the requirement is normally to evaluate the object and allow or deny it without changing the requested resource.
- ✗
AdmissionWebhook
Why it's wrong here
AdmissionWebhook is a colloquial term, not an actual API kind in any built-in Kubernetes group. The API server speaks about AdmissionReview from the admission.k8s.io/v1 group in the webhook payload, but there is no resource named AdmissionWebhook. Submitting such a resource would return a 'no matches for kind' error, so it cannot be part of the audit configuration.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.