Courseiva
Cluster Setup →mediumMultiple Choice

CKS Cluster Setup Practice Question

A security team wants to ensure that all communication between the kubelet and the API server is encrypted. Which flag must be set on the kubelet to enforce this?

⚠ Common exam trap

Many candidates confuse `--tls-cert-file` (which secures the kubelet's own server) with the flag that secures outbound kubelet-to-API-server communication, leading them to pick Option A instead of the correct `--kubeconfig`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

--kubeconfig

The `--kubeconfig` flag on the kubelet specifies the path to a kubeconfig file that contains the credentials and server address for the API server. When this flag is set, the kubelet uses TLS to authenticate and encrypt all communication with the API server, as the kubeconfig file typically references an HTTPS endpoint and includes client certificates or tokens. Without this flag, the kubelet may fall back to insecure or unencrypted connections, violating the requirement for encrypted communication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    --tls-cert-file

    Why it's wrong here

    The --tls-cert-file flag on the kubelet specifies the x509 certificate used to serve the kubelet's own HTTPS endpoints, such as /pods and /healthz. It does not influence how the kubelet authenticates itself when acting as a client to the API server. Client-side TLS for that connection is configured entirely by the kubeconfig file, including the server URL and credentials.

  • ✗

    --node-status-update-frequency

    Why it's wrong here

    The --node-status-update-frequency flag controls how often the kubelet posts node status and pod status updates to the API server. While these updates are part of kubelet-to-API-server traffic, the flag only changes the cadence of those updates, not the transport security. Encryption is determined by the TLS settings in the kubeconfig (e.g., an HTTPS server address) and the cluster's CA trust, so adjusting this flag has no impact on whether communication is encrypted.

  • ✓

    --kubeconfig

    Why this is correct

    The --kubeconfig flag is the correct mechanism because the kubeconfig file defines the API server endpoint (typically an HTTPS URL), the CA certificate used to verify the server, and the kubelet's client credentials for authentication. When the kubelet starts with --kubeconfig, it uses this file to establish a mutually authenticated, TLS-encrypted connection to the API server. Requiring a kubeconfig that points to the API server over HTTPS ensures all control-plane traffic from the kubelet is encrypted in transit.

  • ✗

    --require-kubeconfig

    Why it's wrong here

    The --require-kubeconfig flag is deprecated and only forces the kubelet to load a kubeconfig at startup, failing if none is present. It does not specify the server address, enable TLS, or enforce encryption; it simply guards against an insecure fallback to a local API server. In modern Kubernetes, this flag is effectively a no-op because the kubelet always requires a kubeconfig, and it cannot address the security team's goal of ensuring encrypted communication.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.