CKS Supply Chain Security Practice Question
An admin runs 'kubectl run test-pod --image=nginx:latest' and the Pod is created but immediately enters 'CrashLoopBackOff'. 'kubectl describe pod test-pod' shows 'Back-off restarting failed container'. Which admission controller might cause this if misconfigured?
⚠ Common exam trap
Many exam-takers assume a Pod entering CrashLoopBackOff must be due to a security policy (PodSecurity) or a validation rejection, but the 'Back-off restarting failed container' message indicates the container ran and failed, which points to a mutation that altered the container's runtime configuration, not a rejection or security constraint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MutatingAdmissionWebhook
A MutatingAdmissionWebhook can modify Pod specifications (e.g., injecting sidecar containers, changing image names, or adding init containers) before the Pod is persisted. If the webhook misconfigures the Pod—such as replacing the image with a non-existent one or adding a failing init container—the container may fail to start, causing a CrashLoopBackOff. The 'Back-off restarting failed container' message indicates the container itself is failing, which aligns with a mutation that breaks the Pod's runtime behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ValidatingAdmissionWebhook
Why it's wrong here
A ValidatingAdmissionWebhook runs during the admission phase and can only accept or reject a request. If it rejected the nginx Pod, the API server would refuse to create it, so no container would ever start. CrashLoopBackOff is a kubelet-level runtime state that requires the Pod to exist and the container to repeatedly fail, so this webhook type cannot produce that outcome.
- ✓
MutatingAdmissionWebhook
Why this is correct
A MutatingAdmissionWebhook can modify the Pod spec before it is persisted, so even a simple nginx image could end up with an altered command, injected sidecar, or changed entrypoint. Once admitted, kubelet runs the mutated container, and if the mutation causes the main process to exit (e.g., a sidecar and no nginx, or an invalid argument), the resulting restart loop appears as CrashLoopBackOff. This explains why a mutation, not an outright rejection, matches the symptom.
- ✗
PodSecurity
Why it's wrong here
PodSecurity (the successor to PSPs) is a validating admission controller that enforces security standards like privileged containers or host namespaces. A violation causes the Pod creation request to be denied entirely, producing an API error instead of a running Pod. Since CrashLoopBackOff happens only after the Pod has been scheduled and the container has started failing, PodSecurity is a pre-creation gate and cannot cause this runtime condition.
- ✗
PersistentVolumeClaimResize
Why it's wrong here
PersistentVolumeClaimResize is a feature that allows expanding a PVC's requested capacity while it is in use by a Pod. It operates on PVC objects and does not affect the Pod spec, container image, or command line. Even if a resize failed or was blocked, that would generate a storage-related event or API error, not a CrashLoopBackOff in an nginx container that doesn't mount a volume.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Container Image Security
Key term
OPA Gatekeeper
OPA Gatekeeper is a Kubernetes admission controller that enforces custom security and compliance policies on resources before they are created or updated in a cluster.
Key term
Node Restriction
A Kubernetes admission controller that limits what a kubelet can modify on its own node to prevent privilege escalation and unauthorized access.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.