Courseiva
mediumMultiple Choice

CKS Practice Question: A cluster administrator wants to ensure that pods…

A cluster administrator wants to ensure that pods cannot modify node objects. Which admission plugin should be enabled?

⚠ Common exam trap

Test-takers frequently confuse admission plugins that affect pod scheduling (like NodeAffinity or PodNodeSelector) with those that enforce node-level security restrictions, leading them to overlook NodeRestriction as the correct answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NodeRestriction

The NodeRestriction admission plugin limits the kubelet's ability to modify node and pod objects to only those nodes it is authorized to manage. This prevents a compromised or misconfigured kubelet from modifying arbitrary node objects, enforcing the principle of least privilege. Option D is correct because it directly addresses the requirement to restrict node object modifications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PodSecurityPolicy

    Why it's wrong here

    PodSecurityPolicy is an admission controller that enforced security context constraints on pod specifications, such as privileged mode, host namespaces, and volume types. It was deprecated in Kubernetes 1.21 and removed in 1.25, but more importantly, it never evaluated requests to create, update, or delete node objects. The plugin only intercepts pod creation and update requests, so it cannot block a process from modifying a Node resource via the API server. Therefore, it is wrong for this scenario.

  • ✗

    NodeAffinity

    Why it's wrong here

    NodeAffinity is a scheduling field inside a pod specification that constrains which nodes a pod can be scheduled onto based on node labels. It is not an admission plugin; it is simply a rule evaluated by the scheduler after a pod is created. It has no ability to inspect or intercept API requests aimed at modifying node objects. Thus, it cannot prevent a pod or its credentials from changing node metadata or status, making it incorrect.

  • ✗

    PodNodeSelector

    Why it's wrong here

    PodNodeSelector is an admission controller that enforces namespace-level node selector restrictions on newly created pods. It works by either defaulting a pod's nodeSelector or rejecting pods that violate the namespace's allowed selector. However, this plugin only affects pod objects and their scheduling constraints; it does not validate or restrict operations on Node objects. Consequently, it cannot prevent modifications to nodes, so it is not the correct answer.

  • ✓

    NodeRestriction

    Why this is correct

    NodeRestriction is an admission controller in the kube-apiserver that enforces the Node authorizer's limits on kubelet API access. It ensures a kubelet can only modify its own Node object, and even then only specific fields like status, labels, and annotations permitted by the authorizer. This plugin directly blocks kubelet-initiated requests that attempt to modify other nodes or the node's spec in unauthorized ways. Because it specifically targets node object modification, it is the correct mechanism described in the question.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.