CKS System Hardening Practice Question
A DevOps team wants to ensure that all container images are pulled from a trusted registry only. Which cluster-level configuration should be applied?
⚠ Common exam trap
CNCF often tests the distinction between admission controllers that validate image sources (ImagePolicyWebhook) versus those that enforce Pod security contexts (PodSecurity), leading candidates to mistakenly choose PodSecurity when the question is about registry trust.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable ImagePolicyWebhook admission controller
The ImagePolicyWebhook admission controller allows you to configure a cluster-level admission plugin that intercepts all Pod creation requests and validates the container images against an external webhook backend. This backend can enforce policies such as allowing only images from a trusted registry (e.g., `mytrustedregistry.io/*`), rejecting any image that does not match the whitelist. It operates at the API server level, ensuring that no Pod with an untrusted image can be created in the cluster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure kubelet with --pod-manifest-path pointing to a whitelist
Why it's wrong here
The --pod-manifest-path kubelet flag designates a directory from which the kubelet creates static pods; it is not a registry allowlist. Static pods bypass the API server and admission controllers, so they could still pull from untrusted registries, and regular API-managed workloads would be completely unaffected. This flag can only control which manifest files are read on a single node, not the image source of every Pod in the cluster.
- ✗
Enable PodSecurity with restricted profile
Why it's wrong here
PodSecurity with a restricted profile enforces Kubernetes Pod Security Standards, such as running as non-root, dropping capabilities, and avoiding privileged containers. Its admission evaluation only examines the Pod spec's security context fields, not the image field or the registry that hosts it. Therefore, a Pod could satisfy every restricted requirement while still using a container image fetched from an untrusted repository.
- ✗
Use NetworkPolicy to block traffic to untrusted registries
Why it's wrong here
NetworkPolicy objects control layer 3/4 traffic to and from Pods in the selected namespaces, but image pulls are performed by the kubelet and container runtime on the node using the host network, before any Pod network namespace exists. Even if network policy blocked egress to a registry, it wouldn't be an admission decision about the image source, and cached or pre-pulled images would still run. It can affect runtime connectivity but cannot guarantee image provenance.
- ✓
Enable ImagePolicyWebhook admission controller
Why this is correct
ImagePolicyWebhook is an admission controller that intercepts Pod create and update operations and sends an ImageReview payload containing each container's image name to an external HTTP/HTTPS service. The webhook responds with an admission decision, allowing an administrator to reject any image that doesn't come from a trusted registry, tag, or digest. This is the standard built-in mechanism for applying a centralized, registry-aware image policy to every Pod submitted through the API server.
Go deeper
Related to this question
Learn chapter
Cluster Hardening: Node and Container Security
Key term
Node Restriction
A Kubernetes admission controller that limits what a kubelet can modify on its own node to prevent privilege escalation and unauthorized access.
Key term
OPA Gatekeeper
OPA Gatekeeper is a Kubernetes admission controller that enforces custom security and compliance policies on resources before they are created or updated in a cluster.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.