Courseiva
Supply Chain Security →hardMultiple Choice

CKS Supply Chain Security Practice Question

A security engineer wants to ensure that all container images in a Kubernetes cluster have a non-root user. Which admission controller can enforce this requirement?

⚠ Common exam trap

A common pitfall is selecting PodSecurityPolicy because it was the traditional way to enforce security policies, but it is deprecated and removed in newer Kubernetes versions. The question specifically asks for an admission controller that can enforce a non-root user requirement. Built-in controllers like ServiceAccount or NodeRestriction cannot enforce custom pod security policies. Kyverno (and OPA/Gatekeeper) are Kubernetes-native policy engines that act as dynamic admission controllers to validate or mutate pod specs. Candidates often overlook that Kyverno is a valid admission controller for such custom rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Kyverno

Kyverno is a Kubernetes-native policy engine that can enforce custom admission control rules, such as requiring containers to run as a non-root user. Unlike deprecated or built-in controllers, Kyverno allows you to define fine-grained policies (e.g., `autogen-check`) that validate or mutate Pod specs to ensure `runAsNonRoot: true` or `runAsUser: >0`.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ServiceAccount

    Why it's wrong here

    ServiceAccounts act as the identity for pods and workloads, enabling authentication to the Kubernetes API server and authorization through RBAC. However, a ServiceAccount definition contains no fields that inspect or enforce security context settings like runAsNonRoot, and it cannot mandate that containers execute as a non-root user. It is purely an identity mechanism, not an admission policy or security context enforcer.

  • ✗

    PodSecurityPolicy (deprecated)

    Why it's wrong here

    PodSecurityPolicy (PSP) was a deprecated admission controller that could enforce security context constraints such as runAsNonRoot, but it was removed in Kubernetes v1.25 and is no longer available. PSP was also notoriously complex to configure and created inherent privilege-escalation risks, leading to its replacement by Pod Security Admission or policy engines. Since a security engineer should not rely on deprecated, removed components, PSP is not a valid current solution.

  • ✗

    NodeRestriction

    Why it's wrong here

    NodeRestriction is an admission controller that limits the permissions of kubelets on nodes, preventing a node from modifying objects owned by other nodes or the cluster control plane. It has no awareness of pod specifications, container images, or security contexts, and it cannot enforce requirements like runAsNonRoot. Its purpose is node authorization and API-safety, not workload policy enforcement.

  • ✓

    Kyverno

    Why this is correct

    Kyverno is a Kubernetes-native policy engine running as an admission controller that can validate, mutate, and generate resources. It can define a ClusterPolicy requiring runAsNonRoot: true on every pod, and can even automatically mutate pods to set a non-root security context. Kyverno uses validating and mutating webhooks to intercept pod creation, making it a robust and current tool for guaranteeing container images run as non-root across the cluster.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.