CKS Minimize Microservice Vulnerabilities Practice Question
An admin creates the following EncryptionConfiguration to encrypt secrets at rest. After applying it, what must the admin do to ensure existing secrets are encrypted?
⚠ Common exam trap
A common misconception is that applying an EncryptionConfiguration automatically encrypts all existing data, but the trap here is that encryption at rest only applies to new or updated writes, not to data already stored in etcd.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Re-create the existing secrets
When an EncryptionConfiguration is applied to encrypt secrets at rest, the kube-apiserver uses the configured encryption provider to encrypt new or updated secrets as they are written to etcd. However, existing secrets that were stored in plaintext before the configuration was applied remain unencrypted in etcd. To ensure these existing secrets are encrypted, the admin must re-create them (e.g., by deleting and recreating them or using `kubectl get secret -o yaml | kubectl replace -f -`), which triggers a write to etcd through the encryption provider.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Re-create the existing secrets
Why this is correct
Existing secrets are stored in etcd with the identity provider (plaintext) until they are rewritten. Enabling an encryption provider in the EncryptionConfiguration only affects future write operations; the kube-apiserver does not retroactively scan or encrypt existing entries. To force encryption, you must re-create each secret (e.g., via kubectl get secret -o yaml | kubectl replace -f -) so the apiserver writes the new record using the configured encryption provider.
- ✗
Restart the kube-apiserver
Why it's wrong here
Restarting the kube-apiserver is indeed required to load the updated EncryptionConfiguration file, but it does not cause a rewrite of existing etcd data. During startup, the apiserver only initializes the provider list; it never iterates over current secrets to re-encrypt them. Only subsequent writes—such as secret re-creation or updates—will be encrypted, so existing plaintext secrets remain untouched in etcd after a restart alone.
- ✗
Delete the existing secrets and wait for them to be recreated automatically
Why it's wrong here
Deleting secrets does not guarantee they will be recreated; this only happens if a controller (e.g., a Deployment or StatefulSet) actively manages the secret's lifecycle, and even then it does so asynchronously and not necessarily with the same data. For manually created secrets, deletion permanently removes them without any automatic replacement. The correct approach is to intentionally re-create the secret from its desired spec, which also triggers encryption on the write path.
- ✗
Nothing, the existing secrets are automatically encrypted
Why it's wrong here
Existing secrets are not automatically encrypted when the EncryptionConfiguration changes because encryption happens at write time, not read time. When the apiserver started without encryption, all secrets were written with the identity provider and stored as raw JSON in etcd. To convert them, a write operation (re-create or update) is required; otherwise they remain plaintext indefinitely, even after the apiserver learns to decrypt encrypted data.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.