hardMultiple Choice
CKS Practice Question: A cluster has been configured with the…
A cluster has been configured with the NodeRestriction admission plugin. A developer tries to create a pod that uses a hostPath volume pointing to /var/log. The pod's nodeSelector is set to 'kubernetes.io/hostname: worker-1'. Which statement is true?
⚠ Common exam trap
Test-takers frequently confuse NodeRestriction with other admission plugins like PodSecurityPolicy or think it enforces broad security restrictions, when in fact it only targets node label and kubelet certificate behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The pod will be created because NodeRestriction does not restrict hostPath volumes.
The NodeRestriction admission plugin limits the node labels that a kubelet can set and restricts pods from modifying their node affinity to gain access to node-specific resources. However, it does not restrict the use of hostPath volumes. Therefore, a pod with a hostPath volume pointing to /var/log and a nodeSelector for 'worker-1' will be created, as long as the nodeSelector matches an existing node label and the hostPath volume is otherwise permitted by the PodSecurityPolicy or other security contexts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The pod will be created only if the node label matches the nodeSelector; the hostPath volume is irrelevant.
Why it's wrong here
The kubelet's NodeRestriction admission controller evaluates Node object mutations, not Pod manifests. nodeSelector is a scheduling constraint the kubelet checks when placing a pod onto a node, so a label mismatch would prevent scheduling, not API admission. The hostPath volume is similarly outside NodeRestriction's scope entirely; pod creation is allowed by the API server independently of whether the volume is later mounted.
- ✗
The pod will be rejected because hostPath volumes are not allowed by NodeRestriction.
Why it's wrong here
NodeRestriction is specifically designed to limit kubelet modifications to its own Node object — primarily status updates, labels, and taints — and has no logic for inspecting pod volumes. Volumes are evaluated by admission plugins such as PodSecurity, which enforces baseline/restricted policies, or by custom policies like OPA Gatekeeper. Rejecting a pod solely for a hostPath would require one of those volume-aware controllers, not NodeRestriction.
- ✓
The pod will be created because NodeRestriction does not restrict hostPath volumes.
Why this is correct
The pod is admitted because the NodeRestriction admission controller only limits the kubelet's ability to update Node resources, such as preventing it from changing arbitrary labels or taints on nodes it does not own. It does not evaluate Pod specs at all, so a hostPath volume within a pod is unaffected. HostPath usage is instead constrained by Pod Security Standards or cluster-specific admission policies.
- ✗
The pod will be rejected because the nodeSelector conflicts with the NodeRestriction plugin.
Why it's wrong here
There is no interaction between NodeRestriction and the nodeSelector field because they operate at different layers of the Kubernetes request flow. NodeRestriction intercepts requests from the kubelet user agent (system:node:*) mutating Node objects, while nodeSelector is a pure scheduling hint consumed by the kube-scheduler. A conflict would only arise if the pod were scheduled to a node whose labels do not satisfy the selector, which is a scheduling failure, not an admission rejection.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.