Courseiva
Cluster Hardening →mediumMultiple Choice

CKS Cluster Hardening Practice Question

A cluster uses RBAC and a ServiceAccount 'monitor' in namespace 'observability'. The account needs to list pods in all namespaces. Which ClusterRole and binding should be created?

⚠ Common exam trap

Watch out — candidates often confuse RoleBindings with ClusterRoleBindings, thinking a RoleBinding can grant cluster-wide access if the role is a ClusterRole, but in reality the binding's scope (namespace vs. cluster) determines the effective scope of the permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ClusterRole with 'list' on pods, ClusterRoleBinding

A ServiceAccount that needs to list pods across all namespaces requires a ClusterRole with the 'list' verb on pods, because ClusterRoles are not namespaced and can grant permissions cluster-wide. A ClusterRoleBinding is necessary to bind that ClusterRole to the ServiceAccount, as RoleBindings only apply within a single namespace and cannot grant cluster-scoped permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Role with 'list' on pods, RoleBinding in observability

    Why it's wrong here

    A Role is always namespace-scoped; it can only grant permissions inside the namespace where it is created. Here, the Role is defined in the observability namespace and bound there, so the monitor ServiceAccount can list pods only in that namespace, not across the cluster. If the monitoring requirement spans all namespaces, this configuration fails due to scope limitation, regardless of the correct 'list' verb.

  • ✗

    ClusterRole with 'get' on pods, ClusterRoleBinding

    Why it's wrong here

    The 'get' verb allows retrieving a single pod by name, but it does not permit enumeration or listing of pods. For monitoring use cases that need to discover all pods in the cluster, 'list' (or 'watch') is required. ClusterRoleBinding gives the right scope, but the verb is too restrictive, so this combination cannot fulfill the requirement.

  • ✗

    ClusterRole with 'list' on pods, RoleBinding in observability

    Why it's wrong here

    Even though the ClusterRole itself has cluster-wide scope, a RoleBinding can only grant permissions within the namespace where the binding exists. In this option, the RoleBinding is placed in observability, so the monitor ServiceAccount only receives the 'list' permission for pods in that namespace. Lacking a ClusterRoleBinding, this configuration incorrectly narrows the effective authorization to a single namespace.

  • ✓

    ClusterRole with 'list' on pods, ClusterRoleBinding

    Why this is correct

    A ClusterRole is not bound to any namespace, and a ClusterRoleBinding grants its permissions cluster-wide or across all namespaces. By combining the 'list' verb on pods with these two cluster-scoped resources, the monitor ServiceAccount can list pods in every namespace. This is the standard and correct way to grant cross-namespace pod enumeration in RBAC.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.