CKS Supply Chain Security Practice Question
A security engineer wants to ensure that all container images in a Kubernetes cluster have a non-root user. Which admission controller can enforce this requirement?
⚠ Common exam trap
A common pitfall is selecting PodSecurityPolicy because it was the traditional way to enforce security policies, but it is deprecated and removed in newer Kubernetes versions. The question specifically asks for an admission controller that can enforce a non-root user requirement. Built-in controllers like ServiceAccount or NodeRestriction cannot enforce custom pod security policies. Kyverno (and OPA/Gatekeeper) are Kubernetes-native policy engines that act as dynamic admission controllers to validate or mutate pod specs. Candidates often overlook that Kyverno is a valid admission controller for such custom rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kyverno
Kyverno is a Kubernetes-native policy engine that can enforce custom admission control rules, such as requiring containers to run as a non-root user. Unlike deprecated or built-in controllers, Kyverno allows you to define fine-grained policies (e.g., `autogen-check`) that validate or mutate Pod specs to ensure `runAsNonRoot: true` or `runAsUser: >0`.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ServiceAccount
Why it's wrong here
ServiceAccounts act as the identity for pods and workloads, enabling authentication to the Kubernetes API server and authorization through RBAC. However, a ServiceAccount definition contains no fields that inspect or enforce security context settings like runAsNonRoot, and it cannot mandate that containers execute as a non-root user. It is purely an identity mechanism, not an admission policy or security context enforcer.
- ✗
PodSecurityPolicy (deprecated)
Why it's wrong here
PodSecurityPolicy (PSP) was a deprecated admission controller that could enforce security context constraints such as runAsNonRoot, but it was removed in Kubernetes v1.25 and is no longer available. PSP was also notoriously complex to configure and created inherent privilege-escalation risks, leading to its replacement by Pod Security Admission or policy engines. Since a security engineer should not rely on deprecated, removed components, PSP is not a valid current solution.
- ✗
NodeRestriction
Why it's wrong here
NodeRestriction is an admission controller that limits the permissions of kubelets on nodes, preventing a node from modifying objects owned by other nodes or the cluster control plane. It has no awareness of pod specifications, container images, or security contexts, and it cannot enforce requirements like runAsNonRoot. Its purpose is node authorization and API-safety, not workload policy enforcement.
- ✓
Kyverno
Why this is correct
Kyverno is a Kubernetes-native policy engine running as an admission controller that can validate, mutate, and generate resources. It can define a ClusterPolicy requiring runAsNonRoot: true on every pod, and can even automatically mutate pods to set a non-root security context. Kyverno uses validating and mutating webhooks to intercept pod creation, making it a robust and current tool for guaranteeing container images run as non-root across the cluster.
Go deeper
Related to this question
Learn chapter
Kubernetes Security Fundamentals
Key term
Node Restriction
A Kubernetes admission controller that limits what a kubelet can modify on its own node to prevent privilege escalation and unauthorized access.
Key term
OPA Gatekeeper
OPA Gatekeeper is a Kubernetes admission controller that enforces custom security and compliance policies on resources before they are created or updated in a cluster.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.