mediumMultiple Choice
CKS Practice Question: A security auditor runs kube-bench on a…
A security auditor runs kube-bench on a Kubernetes node and reports that the check '1.1.1 Ensure that the API server pod specification file permissions are set to 644 or more restrictive' fails. What is the most appropriate remediation?
⚠ Common exam trap
Watch out — candidates often assume a service restart is required after a file permission change, but the kubelet automatically detects manifest file modifications, making a restart redundant and incorrect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run 'chmod 644 /etc/kubernetes/manifests/kube-apiserver.yaml'
The CIS benchmark for Kubernetes requires the API server manifest file to have permissions of 644 or more restrictive (e.g., 600, 640, or 644) to prevent unauthorized modifications. Running 'chmod 644 /etc/kubernetes/manifests/kube-apiserver.yaml' sets the file to read-write for the owner and read-only for group and others, satisfying the benchmark. The kubelet automatically detects the change and reloads the static pod, so no restart is needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the API server manifest file
Why it's wrong here
Deleting the API server manifest file would cause kubelet to terminate the static pod it manages, bringing down the Kubernetes API server and effectively halting cluster control plane operations. This destructive action is not a remediation for a file permission issue and would cause a significant outage. The correct approach is to adjust the file mode, not remove the configuration.
- ✗
Run 'chmod 755 /etc/kubernetes/manifests/kube-apiserver.yaml'
Why it's wrong here
chmod 755 sets the manifest to rwxr-xr-x, which grants world-read and world-execute permissions. The CIS Kubernetes Benchmark requires the file to be 644 or more restrictive (e.g., 600), so 755 fails the audit because it is less restrictive than the required baseline. Additionally, executing a YAML manifest serves no purpose; this mode only increases the attack surface for unauthorized users to inspect the file.
- ✗
Restart the kubelet service
Why it's wrong here
Restarting the kubelet service forces it to re-read the manifest directory, but it does not alter the file system permissions on the manifest file. The kubelet runs as root and can read the file regardless of its mode; however, the security audit checks the actual permissions on disk. A restart only causes unnecessary downtime and does not address the audit finding, which requires a chmod command.
- ✓
Run 'chmod 644 /etc/kubernetes/manifests/kube-apiserver.yaml'
Why this is correct
chmod 644 sets the file mode to rw-r--r--, granting read access to all users but write access only to the owner (root). This satisfies the CIS Kubernetes Benchmark requirement that control plane manifest files be 644 or more restrictive, preventing unprivileged users from modifying the API server configuration. Because the kubelet reads these manifests as root, read permission is sufficient, and the removal of group/other write permission aligns with least privilege.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.