Courseiva
mediumMultiple Choice

CKS Practice Question: A security audit reveals that the etcd datastore…

A security audit reveals that the etcd datastore is not encrypted at rest. Which resource should be created to enable encryption of secrets at rest?

⚠ Common exam trap

CNCF often tests the exact API resource name, and candidates mistakenly pick 'EtcdEncryption' or 'EncryptionConfig' because they sound plausible, but only 'EncryptionConfiguration' is the correct Kubernetes resource defined in the apiserver configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EncryptionConfiguration

To enable encryption of secrets at rest in Kubernetes, you must create an EncryptionConfiguration resource. This resource defines which encryption providers (e.g., AES-CBC, secretbox) to use and how to encrypt resources stored in etcd. The kube-apiserver reads this configuration via the --encryption-provider-config flag and applies it to all resources in the specified resource group, such as secrets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    EncryptionConfiguration

    Why this is correct

    EncryptionConfiguration is the correct Kubernetes API resource, defined in the apiserver.config.k8s.io/v1 API group, that specifies how etcd data is encrypted at rest. It declares an ordered list of providers (identity, aescbc, aesgcm, secretbox, or kms) and the corresponding keys; the kube-apiserver reads it via --encryption-provider-config. This is the only one of these options that actually exists as a first-class configuration object.

  • ✗

    EtcdEncryption

    Why it's wrong here

    EtcdEncryption is not a registered Kubernetes API resource and no such kind exists in any API group. etcd is the backend datastore itself, not a configuration object; encryption is configured on the API server, not on etcd directly. A valid object would be a kind under apiserver.config.k8s.io, never 'EtcdEncryption'.

  • ✗

    EncryptionConfig

    Why it's wrong here

    EncryptionConfig is an invalid name; the Kubernetes resource is always EncryptionConfiguration, not a shortened or abbreviated variant. Unlike some legacy command-line flags that were informally called 'encryption config', this string is not a Kind that the API server recognizes or can process. Using this name would cause the API server to reject the manifest or request, so it cannot enable encryption at rest.

  • ✗

    SecretEncryption

    Why it's wrong here

    SecretEncryption is not a Kubernetes API resource; while Secrets are a primary target of encryption at rest, they do not have their own encryption configuration object. The encryption configuration is cluster-level and applies to all supported resources (Secrets, ConfigMaps, etc.) via the API server, not a per-kind object. This name is also not registered in apiserver.config.k8s.io, making it invalid.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.