mediumMultiple Choice
CKS Practice Question: A security auditor runs kube-bench and reports…
A security auditor runs kube-bench and reports that the kubelet is not configured with --protect-kernel-defaults. What is the impact of this misconfiguration?
⚠ Common exam trap
It's easy for candidates to assume a missing security flag will cause an immediate failure (like kubelet not starting), when in reality the kubelet runs but the node becomes vulnerable to kernel parameter tampering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kernel parameters may be modified, potentially reducing node security
The `--protect-kernel-defaults` flag ensures that the kubelet enforces kernel parameter hardening, preventing modifications that could weaken node security. Without it, a compromised or misconfigured pod could alter kernel settings (e.g., `net.ipv4.ip_forward`, `vm.overcommit_memory`), reducing the overall security posture of the node. This does not affect image pulling, pod scheduling, or kubelet startup.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Container runtime will not be able to pull images
Why it's wrong here
Image pulling is executed by the container runtime (containerd, CRI-O, etc.) through the kubelet's image service, which handles registry authentication and layer downloads independently of the --protect-kernel-defaults flag. This kubelet flag exclusively governs whether kernel tunables (sysctls) are validated and protected, and its absence has no effect on the code paths that fetch images. Thus, omitting the flag cannot disrupt image pulling; it only disables enforcement of recommended kernel security settings.
- ✗
The node will be unable to schedule pods
Why it's wrong here
Pod scheduling is performed by the kube-scheduler based on node taints, tolerations, resource capacity, and the node's readiness as reported by the kubelet's status updates. The absence of --protect-kernel-defaults does not alter kubelet's liveness or readiness, nor does it change the node object's schedulable state, so the scheduler will continue to place pods on the node. This flag affects only kernel-default enforcement, which is a separate concern from the scheduling pipeline.
- ✗
The kubelet will refuse to start
Why it's wrong here
Missing --protect-kernel-defaults does not cause kubelet to refuse to start because the flag defaults to false; kubelet launches normally and simply skips verification of kernel parameter values. If the flag were explicitly set to true and the node's kernel tunables did not match kubelet's expected secure defaults, then kubelet would terminate at startup—but that is a different scenario. Here, the flag's absence lowers security but does not affect kubelet's process lifecycle or ability to boot.
- ✓
Kernel parameters may be modified, potentially reducing node security
Why this is correct
Without --protect-kernel-defaults, kubelet does not verify that kernel parameters such as kernel.panic, vm.overcommit_memory, or net.ipv4.ip_forward match the secure values required by the CIS Kubernetes Benchmark, nor does it prevent containers from applying unsafe sysctls that can alter node-wide kernel behavior. A pod could thus modify kernel settings (e.g., enabling IP forwarding, changing shared-memory limits, or altering panic behavior), weakening node isolation and potentially facilitating container escapes or lateral network movement. Setting the flag to true forces kubelet to enforce these defaults or refuse to start, preserving node security.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.