CKS Cluster Hardening Practice Question
A cluster uses RBAC and a ServiceAccount 'monitor' in namespace 'observability'. The account needs to list pods in all namespaces. Which ClusterRole and binding should be created?
⚠ Common exam trap
Watch out — candidates often confuse RoleBindings with ClusterRoleBindings, thinking a RoleBinding can grant cluster-wide access if the role is a ClusterRole, but in reality the binding's scope (namespace vs. cluster) determines the effective scope of the permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ClusterRole with 'list' on pods, ClusterRoleBinding
A ServiceAccount that needs to list pods across all namespaces requires a ClusterRole with the 'list' verb on pods, because ClusterRoles are not namespaced and can grant permissions cluster-wide. A ClusterRoleBinding is necessary to bind that ClusterRole to the ServiceAccount, as RoleBindings only apply within a single namespace and cannot grant cluster-scoped permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Role with 'list' on pods, RoleBinding in observability
Why it's wrong here
A Role is always namespace-scoped; it can only grant permissions inside the namespace where it is created. Here, the Role is defined in the observability namespace and bound there, so the monitor ServiceAccount can list pods only in that namespace, not across the cluster. If the monitoring requirement spans all namespaces, this configuration fails due to scope limitation, regardless of the correct 'list' verb.
- ✗
ClusterRole with 'get' on pods, ClusterRoleBinding
Why it's wrong here
The 'get' verb allows retrieving a single pod by name, but it does not permit enumeration or listing of pods. For monitoring use cases that need to discover all pods in the cluster, 'list' (or 'watch') is required. ClusterRoleBinding gives the right scope, but the verb is too restrictive, so this combination cannot fulfill the requirement.
- ✗
ClusterRole with 'list' on pods, RoleBinding in observability
Why it's wrong here
Even though the ClusterRole itself has cluster-wide scope, a RoleBinding can only grant permissions within the namespace where the binding exists. In this option, the RoleBinding is placed in observability, so the monitor ServiceAccount only receives the 'list' permission for pods in that namespace. Lacking a ClusterRoleBinding, this configuration incorrectly narrows the effective authorization to a single namespace.
- ✓
ClusterRole with 'list' on pods, ClusterRoleBinding
Why this is correct
A ClusterRole is not bound to any namespace, and a ClusterRoleBinding grants its permissions cluster-wide or across all namespaces. By combining the 'list' verb on pods with these two cluster-scoped resources, the monitor ServiceAccount can list pods in every namespace. This is the standard and correct way to grant cross-namespace pod enumeration in RBAC.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.