Courseiva
mediumMultiple Choice

CKS Practice Question: A cluster administrator wants to encrypt secrets…

A cluster administrator wants to encrypt secrets at rest in etcd. Which resource must be created to configure encryption?

⚠ Common exam trap

Candidates often confuse the generic term 'encryption config' with the exact Kubernetes API resource name 'EncryptionConfiguration', or they mistakenly think a KMS provider is a standalone resource rather than a provider type within the EncryptionConfiguration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EncryptionConfiguration

The correct resource is an EncryptionConfiguration object, which is a Kubernetes API resource that defines how to encrypt secrets at rest in etcd. It specifies providers (such as aesgcm, secretbox, or kms) and their order of precedence for encrypting and decrypting data. This configuration is passed to the kube-apiserver via the --encryption-provider-config flag.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    KMSProvider

    Why it's wrong here

    KMSProvider is not a Kubernetes resource for configuring encryption at rest; it is a provider type that appears inside an EncryptionConfiguration object. The valid resource is the EncryptionConfiguration, and within its providers list you can specify kms, aescbc, aesgcm, secretbox, or identity. Using 'KMSProvider' as a standalone resource name is incorrect because the API server only recognizes the top-level EncryptionConfiguration kind.

  • ✓

    EncryptionConfiguration

    Why this is correct

    EncryptionConfiguration is the exact Kubernetes API resource used to configure encryption at rest. It is an object from the apiserver.config.k8s.io/v1 API group, and it defines a providers list that determines how the API server encrypts resources like Secrets before writing them to etcd. The API server loads this object via the --encryption-provider-config flag, making it the correct and only valid resource for this purpose.

  • ✗

    SecretEncryptionConfig

    Why it's wrong here

    SecretEncryptionConfig is not a Kubernetes resource; no such API kind exists. It may sound plausible or resemble cloud-provider-specific configurations, but Kubernetes has standardized on the name EncryptionConfiguration. Any attempt to create a SecretEncryptionConfig would be rejected by the API server because there is no registered kind with that name.

  • ✗

    EncryptionConfig

    Why it's wrong here

    EncryptionConfig is an invalid and non-existent resource name; it is likely a shorthand or misnomer for EncryptionConfiguration. The actual API kind is EncryptionConfiguration (with the full 'Configuration' suffix), and the YAML manifest must use `kind: EncryptionConfiguration`. A resource called EncryptionConfig would not be recognized by Kubernetes, so it cannot be used to enable encryption at rest.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.