hardMultiple Choice
CKS Practice Question: A pod in namespace 'ns1' has…
A pod in namespace 'ns1' has automountServiceAccountToken: false. However, the container still has a mounted service account token at /var/run/secrets/kubernetes.io/serviceaccount. What is the most likely cause?
⚠ Common exam trap
It's easy for candidates to assume setting `automountServiceAccountToken: false` anywhere in the pod YAML will work, but they overlook that it must be at the pod spec level, not inside a container definition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The automountServiceAccountToken field is set in the container spec instead of the pod spec
The `automountServiceAccountToken` field is a pod-level setting. If it is set to `false` in the pod spec, the kubelet will not automatically mount the service account token. However, if the field is mistakenly set inside a container spec (which is not a valid field for containers), the pod-level setting is ignored, and the default behavior (mounting the token) applies. This is why the token still appears mounted despite the intention to disable it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The automountServiceAccountToken field is set in the container spec instead of the pod spec
Why this is correct
The `automountServiceAccountToken` field is a valid field only in the pod spec (via `PodSpec`); it is not part of the container spec. When placed under a container entry, Kubernetes ignores it or rejects it as an unknown field depending on the API server's validation strictness, so the pod-level field remains unset and defaults to `true`. Consequently, the kubelet mounts the service account token into all containers because the pod itself never disabled automounting.
- ✗
The kubelet is configured to always mount tokens
Why it's wrong here
There is no kubelet configuration that forces service account token mounting for all pods; the kubelet only honors the `automountServiceAccountToken` field in the pod spec (or the effective setting from the service account). Even if such a flag existed, it would contradict Kubernetes' per-pod security model and would require a feature gate, not a simple kubelet flag. The presence or absence of the token is therefore determined entirely by pod and service account configuration, not by kubelet settings.
- ✗
The namespace has a default automountServiceAccountToken: true
Why it's wrong here
Kubernetes does not have a namespace-level `automountServiceAccountToken` default; that field exists only on `PodSpec` and `ServiceAccount`. The pod's own setting takes precedence over any inherited or default value, so if the pod spec explicitly set `automountServiceAccountToken: false`, the token would not be mounted regardless of any hypothetical namespace default. Because no such namespace mechanism exists, this cannot explain why the token is present.
- ✗
The pod is using a custom service account with automountServiceAccountToken: true
Why it's wrong here
When both the pod spec and the service account specify `automountServiceAccountToken`, the pod-level value wins; a service account's `true` cannot override a pod's `false`. The kubelet reads the effective `PodSpec` field after merging service account settings, so a custom service account with `automountServiceAccountToken: true` would only matter if the pod did not explicitly set the field. This option would imply a precedence that Kubernetes does not implement, making it an incorrect explanation for the observed token mount.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.