CKS Cluster Hardening Practice Question
A Kubernetes administrator is reviewing the cluster's RBAC configuration and notices that a ClusterRoleBinding grants the cluster-admin role to the system:anonymous user. What is the most immediate and appropriate action to harden the cluster?
⚠ Common exam trap
The trap here is assuming that RBAC supports deny rules or that other admission controllers can override excessive permissions, when in fact RBAC is purely additive and the binding must be removed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Delete the ClusterRoleBinding to revoke anonymous cluster-admin access.
The most immediate action is to delete the ClusterRoleBinding that grants cluster-admin to system:anonymous. This binding allows unauthenticated users to have full administrative privileges, which is a severe security risk. Removing it eliminates the exposure. Other options either do not address the binding or rely on incorrect RBAC mechanics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add an RBAC rule to deny all actions for system:anonymous.
Why it's wrong here
RBAC is additive; there are no deny rules. You cannot explicitly deny actions via RBAC. The only way to revoke permissions is to remove the binding or role that grants them. Adding a deny rule is not possible and would not work. This option reflects a misunderstanding of RBAC's allow-only model and fails to remediate the security issue.
- ✗
Enable the NodeRestriction admission controller to limit anonymous access.
Why it's wrong here
NodeRestriction limits the permissions of kubelets, not anonymous users. It does not affect ClusterRoleBindings for system:anonymous. Enabling it would not remove the dangerous binding and would leave the cluster vulnerable to unauthenticated administrative access. This action is irrelevant to the identified RBAC misconfiguration and fails to address the immediate threat.
- ✓
Delete the ClusterRoleBinding to revoke anonymous cluster-admin access.
Why this is correct
Deleting the ClusterRoleBinding immediately removes the excessive privileges granted to the system:anonymous user, preventing unauthenticated users from performing administrative actions. This is the most direct and critical remediation step to close the security hole. Leaving it in place would allow anyone to take full control of the cluster, so removal is essential for hardening.
- ✗
Modify the ClusterRoleBinding to bind to a specific user instead of system:anonymous.
Why it's wrong here
While changing the subject of the binding would revoke anonymous access, it might inadvertently grant cluster-admin to another user, which could still be a security risk if not carefully chosen. The immediate concern is the anonymous binding; deleting it is simpler and safer. Modifying could leave a misconfiguration if the new subject is not properly vetted, so it is not the best immediate action.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.