mediumMultiple Choice
CKS Practice Question: Is configuring a Kubernetes cluster to meet CIS…
A security engineer is configuring a Kubernetes cluster to meet CIS benchmark recommendations. The cluster uses kubeadm for bootstrapping. Which action should be taken to ensure the kube-apiserver is hardened against unauthorized access?
⚠ Common exam trap
CNCF often tests the distinction between authentication hardening (anonymous-auth) and authorization or encryption controls, leading candidates to confuse enabling encryption at rest (Option C) with preventing unauthorized API access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set --anonymous-auth=false on the kube-apiserver
Setting `--anonymous-auth=false` on the kube-apiserver disables anonymous requests, ensuring that all API requests must be authenticated. This directly addresses CIS benchmark recommendations for hardening the API server against unauthorized access by preventing unauthenticated users from reaching the API.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set --insecure-port=8080 on the kube-apiserver
Why it's wrong here
Enabling --insecure-port=8080 on the kube-apiserver reopens a plain-HTTP listener that bypasses all authentication and authorization checks, allowing anyone with network reachability to issue arbitrary API calls as a highly privileged user. This flag has been deprecated and removed in modern Kubernetes versions because it completely nullifies cluster security, so it would directly worsen the exposure rather than remediate it.
- ✗
Disable the NodeRestriction admission plugin
Why it's wrong here
The NodeRestriction admission plugin is a mandatory hardening layer that limits kubelet credentials to modifying only their own Node and Pod objects. Disabling it grants compromised nodes the ability to manipulate arbitrary cluster resources, substantially increasing the blast radius of a node compromise and defeating the least-privilege principle that the control plane relies on to contain node-level attackers.
- ✗
Enable encryption at rest for secrets in etcd
Why it's wrong here
Encryption at rest for secrets in etcd is an essential defense-in-depth control that protects confidentiality if the etcd datastore is stolen or backed up, but it does nothing to intercept or authenticate live API requests. This question is about preventing unauthenticated HTTP access to the API server, a runtime control-plane concern, so encrypting etcd data cannot address anonymous authentication or any of the other authentication bypass vectors it introduces.
- ✓
Set --anonymous-auth=false on the kube-apiserver
Why this is correct
Setting --anonymous-auth=false is the precise corrective action: it tells the kube-apiserver to reject any request that lacks valid credentials, instead of letting it proceed with the system:anonymous user. This directly neutralizes the unauthorized access vector described in the scenario, forcing every API interaction to authenticate through a recognized mechanism such as client certificates, bearer tokens, or OIDC. It is the officially recommended hardening default for production clusters, though note that kubelet health-check probes may need an explicit authenticated path if they previously relied on anonymous read access.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.