mediumMultiple Choice
CKS Practice Question: A security audit reveals that the etcd datastore…
A security audit reveals that the etcd datastore is not encrypted at rest. Which resource should be created to enable encryption of secrets at rest?
⚠ Common exam trap
CNCF often tests the exact API resource name, and candidates mistakenly pick 'EtcdEncryption' or 'EncryptionConfig' because they sound plausible, but only 'EncryptionConfiguration' is the correct Kubernetes resource defined in the apiserver configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EncryptionConfiguration
To enable encryption of secrets at rest in Kubernetes, you must create an EncryptionConfiguration resource. This resource defines which encryption providers (e.g., AES-CBC, secretbox) to use and how to encrypt resources stored in etcd. The kube-apiserver reads this configuration via the --encryption-provider-config flag and applies it to all resources in the specified resource group, such as secrets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
EncryptionConfiguration
Why this is correct
EncryptionConfiguration is the correct Kubernetes API resource, defined in the apiserver.config.k8s.io/v1 API group, that specifies how etcd data is encrypted at rest. It declares an ordered list of providers (identity, aescbc, aesgcm, secretbox, or kms) and the corresponding keys; the kube-apiserver reads it via --encryption-provider-config. This is the only one of these options that actually exists as a first-class configuration object.
- ✗
EtcdEncryption
Why it's wrong here
EtcdEncryption is not a registered Kubernetes API resource and no such kind exists in any API group. etcd is the backend datastore itself, not a configuration object; encryption is configured on the API server, not on etcd directly. A valid object would be a kind under apiserver.config.k8s.io, never 'EtcdEncryption'.
- ✗
EncryptionConfig
Why it's wrong here
EncryptionConfig is an invalid name; the Kubernetes resource is always EncryptionConfiguration, not a shortened or abbreviated variant. Unlike some legacy command-line flags that were informally called 'encryption config', this string is not a Kind that the API server recognizes or can process. Using this name would cause the API server to reject the manifest or request, so it cannot enable encryption at rest.
- ✗
SecretEncryption
Why it's wrong here
SecretEncryption is not a Kubernetes API resource; while Secrets are a primary target of encryption at rest, they do not have their own encryption configuration object. The encryption configuration is cluster-level and applies to all supported resources (Secrets, ConfigMaps, etc.) via the API server, not a per-kind object. This name is also not registered in apiserver.config.k8s.io, making it invalid.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.