Courseiva
System Hardening →hardMultiple Choice

CKS System Hardening Practice Question

A cluster has enabled the NodeRestriction admission controller. A developer is trying to create a pod with hostNetwork: true but is getting an error. What is the most likely reason?

⚠ Common exam trap

A common mix-up: candidates confuse NodeRestriction (which restricts kubelet node updates) with PodSecurityPolicy or Pod Security Admission (which restrict pod security contexts like hostNetwork), leading them to incorrectly attribute the error to NodeRestriction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The error is unrelated to NodeRestriction; the issue is likely a missing PodSecurityPolicy or Pod Security Admission that denies hostNetwork

The NodeRestriction admission controller only limits node self-updates to kubelet nodes, preventing them from modifying their own labels, taints, or other node objects. It does not block pods with `hostNetwork: true`. The error is most likely caused by a missing PodSecurityPolicy or Pod Security Admission (PSA) that denies pods with `hostNetwork: true`, as these are the mechanisms that enforce host namespace restrictions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The error is unrelated to NodeRestriction; the issue is likely a missing PodSecurityPolicy or Pod Security Admission that denies hostNetwork

    Why this is correct

    The NodeRestriction admission controller only constrains kubelet-authorized requests that modify Node or status Pod objects; it never evaluates pod specs for fields like hostNetwork. A denial mentioning hostNetwork is instead characteristic of either a deprecated PodSecurityPolicy admission plugin or the newer Pod Security Admission (baseline/restricted) which explicitly rejects hostNetwork: true. Therefore the error is not caused by NodeRestriction but by a cluster security policy.

  • ✗

    The NodeRestriction admission controller blocks pods with hostNetwork

    Why it's wrong here

    The NodeRestriction admission controller does not block hostNetwork because its scope is limited to preventing kubelets from changing Node objects beyond their assigned node, modifying their own node's labels/taints, or writing status to pods that don't match a status-owning filter. It inspects the attributes of the API request (user/resource/name), not the hostNetwork field inside a Pod spec. This misconception confuses a node-hardening admission controller with an admission plugin that filters pod-level security features.

  • ✗

    The nodeSelector on the pod conflicts with NodeRestriction

    Why it's wrong here

    NodeRestriction has no mechanism to interpret or reject nodeSelector because it only restricts which objects a kubelet may modify, based on the kubelet's identity and the requested resource name. A pod's nodeSelector is a scheduling constraint that the Kubernetes scheduler uses to select an eligible node, and no admission controller in the NodeRestriction path examines it. Thus a nodeSelector conflict would show up as an unschedulable pod, not as an admission denial.

  • ✗

    The developer lacks RBAC permissions to create pods

    Why it's wrong here

    RBAC authorization occurs before admission controllers and would produce a Forbidden response with a message about 'pods is forbidden', not a hostNetwork-specific denial. A developer who already reaches the admission stage has satisfied RBAC, so NodeRestriction or PSA would be the next possible blocker. The question explicitly names NodeRestriction as the context, but RBAC ineffectiveness is independent from admission controller logic and cannot explain a hostNetwork policy denial.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.