Courseiva
mediumMultiple Choice

CKS Practice Question: Is configuring a Kubernetes cluster to meet CIS…

A security engineer is configuring a Kubernetes cluster to meet CIS benchmark recommendations. The cluster uses kubeadm for bootstrapping. Which action should be taken to ensure the kube-apiserver is hardened against unauthorized access?

⚠ Common exam trap

CNCF often tests the distinction between authentication hardening (anonymous-auth) and authorization or encryption controls, leading candidates to confuse enabling encryption at rest (Option C) with preventing unauthorized API access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set --anonymous-auth=false on the kube-apiserver

Setting `--anonymous-auth=false` on the kube-apiserver disables anonymous requests, ensuring that all API requests must be authenticated. This directly addresses CIS benchmark recommendations for hardening the API server against unauthorized access by preventing unauthenticated users from reaching the API.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set --insecure-port=8080 on the kube-apiserver

    Why it's wrong here

    Enabling --insecure-port=8080 on the kube-apiserver reopens a plain-HTTP listener that bypasses all authentication and authorization checks, allowing anyone with network reachability to issue arbitrary API calls as a highly privileged user. This flag has been deprecated and removed in modern Kubernetes versions because it completely nullifies cluster security, so it would directly worsen the exposure rather than remediate it.

  • ✗

    Disable the NodeRestriction admission plugin

    Why it's wrong here

    The NodeRestriction admission plugin is a mandatory hardening layer that limits kubelet credentials to modifying only their own Node and Pod objects. Disabling it grants compromised nodes the ability to manipulate arbitrary cluster resources, substantially increasing the blast radius of a node compromise and defeating the least-privilege principle that the control plane relies on to contain node-level attackers.

  • ✗

    Enable encryption at rest for secrets in etcd

    Why it's wrong here

    Encryption at rest for secrets in etcd is an essential defense-in-depth control that protects confidentiality if the etcd datastore is stolen or backed up, but it does nothing to intercept or authenticate live API requests. This question is about preventing unauthenticated HTTP access to the API server, a runtime control-plane concern, so encrypting etcd data cannot address anonymous authentication or any of the other authentication bypass vectors it introduces.

  • ✓

    Set --anonymous-auth=false on the kube-apiserver

    Why this is correct

    Setting --anonymous-auth=false is the precise corrective action: it tells the kube-apiserver to reject any request that lacks valid credentials, instead of letting it proceed with the system:anonymous user. This directly neutralizes the unauthorized access vector described in the scenario, forcing every API interaction to authenticate through a recognized mechanism such as client certificates, bearer tokens, or OIDC. It is the officially recommended hardening default for production clusters, though note that kubelet health-check probes may need an explicit authenticated path if they previously relied on anonymous read access.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.