Courseiva
Cluster Hardening →easyMultiple Choice

CKS Cluster Hardening Practice Question

A Kubernetes administrator is reviewing the cluster's RBAC configuration and notices that a ClusterRoleBinding grants the cluster-admin role to the system:anonymous user. What is the most immediate and appropriate action to harden the cluster?

⚠ Common exam trap

The trap here is assuming that RBAC supports deny rules or that other admission controllers can override excessive permissions, when in fact RBAC is purely additive and the binding must be removed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Delete the ClusterRoleBinding to revoke anonymous cluster-admin access.

The most immediate action is to delete the ClusterRoleBinding that grants cluster-admin to system:anonymous. This binding allows unauthenticated users to have full administrative privileges, which is a severe security risk. Removing it eliminates the exposure. Other options either do not address the binding or rely on incorrect RBAC mechanics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add an RBAC rule to deny all actions for system:anonymous.

    Why it's wrong here

    RBAC is additive; there are no deny rules. You cannot explicitly deny actions via RBAC. The only way to revoke permissions is to remove the binding or role that grants them. Adding a deny rule is not possible and would not work. This option reflects a misunderstanding of RBAC's allow-only model and fails to remediate the security issue.

  • ✗

    Enable the NodeRestriction admission controller to limit anonymous access.

    Why it's wrong here

    NodeRestriction limits the permissions of kubelets, not anonymous users. It does not affect ClusterRoleBindings for system:anonymous. Enabling it would not remove the dangerous binding and would leave the cluster vulnerable to unauthenticated administrative access. This action is irrelevant to the identified RBAC misconfiguration and fails to address the immediate threat.

  • ✓

    Delete the ClusterRoleBinding to revoke anonymous cluster-admin access.

    Why this is correct

    Deleting the ClusterRoleBinding immediately removes the excessive privileges granted to the system:anonymous user, preventing unauthenticated users from performing administrative actions. This is the most direct and critical remediation step to close the security hole. Leaving it in place would allow anyone to take full control of the cluster, so removal is essential for hardening.

  • ✗

    Modify the ClusterRoleBinding to bind to a specific user instead of system:anonymous.

    Why it's wrong here

    While changing the subject of the binding would revoke anonymous access, it might inadvertently grant cluster-admin to another user, which could still be a security risk if not carefully chosen. The immediate concern is the anonymous binding; deleting it is simpler and safer. Modifying could leave a misconfiguration if the new subject is not properly vetted, so it is not the best immediate action.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.