CKS System Hardening Practice Question
A cluster uses a custom mutating admission webhook that adds a sidecar container to all pods. After an upgrade, the webhook crashes and pods cannot be created. What is the best way to prevent this scenario in future?
⚠ Common exam trap
Many exam-takers think high availability (multiple replicas) is sufficient, but the CKS exam tests the understanding that failurePolicy is the direct mechanism to prevent a single webhook failure from blocking all pod creation, regardless of replica count.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the webhook's failurePolicy to Ignore
Setting the webhook's failurePolicy to Ignore ensures that if the webhook fails (e.g., crashes or times out), the API server will bypass the webhook and allow the pod creation to proceed. This prevents a single point of failure from blocking all pod creation, which is critical for cluster availability. The default failurePolicy is Fail, which would cause the entire admission request to fail if the webhook is unreachable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run multiple replicas of the webhook
Why it's wrong here
Running multiple replicas of the webhook provides high availability but does not solve the fundamental issue of webhook unavailability due to network partition, misconfiguration, or a bug that crashes all replicas at once. If the webhook is down, the API server still fails closed when failurePolicy=Fail, so multiple replicas reduce but do not eliminate the risk; they also introduce consistency issues if the webhook is stateful.
- ✓
Set the webhook's failurePolicy to Ignore
Why this is correct
Setting failurePolicy: Ignore tells the API server to bypass the webhook if it cannot be reached or returns an error, allowing pod creation to proceed without the mutation. This guarantees availability but at the cost of correctness, as the pod may miss required mutations. It is a standard mitigator for webhook outages, but should be used only when the mutation is non-critical or the mutation can be enforced elsewhere.
- ✗
Disable admission webhooks in the cluster
Why it's wrong here
Disabling admission webhooks in the cluster, for example by changing the kube-apiserver --disable-admission-plugins list, would stop the custom mutating webhook but also disables essential built-in admission controllers like NamespaceLifecycle, LimitRanger, or ServiceAccount. This is a drastic cluster-wide change that undermines security and policy enforcement, and it does not specifically address the webhook outage; it would affect all API requests and require an API server restart.
- ✗
Create a validating webhook as a backup
Why it's wrong here
Creating a validating webhook as a backup does not resolve the outage because validating webhooks sit in the same admission chain and, if unreachable, block or ignore requests based on their own failurePolicy, so they can fail the same way. Additionally, a validating webhook can only observe, not mutate, the pod, so it cannot apply the missing mutations; it could only validate their absence. A second mutating webhook with failurePolicy: Ignore would be needed, but that just replicates the same availability tradeoff.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.