Courseiva
mediumMultiple Choice

CKS Practice Question: An administrator creates an…

An administrator creates an EncryptionConfiguration with aescbc and saves it to /etc/kubernetes/enc/enc.yaml. Which flag must be added to the kube-apiserver to enable encryption at rest?

⚠ Common exam trap

Many candidates confuse the valid `--encryption-provider-config` flag with similar-sounding but invalid flags like `--encryption-config` or `--encryption-provider`, or assume a simple `--enable-encryption` toggle exists, when in reality encryption at rest requires a detailed configuration file.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

--encryption-provider-config=/etc/kubernetes/enc/enc.yaml

The kube-apiserver requires the `--encryption-provider-config` flag to specify the path to the EncryptionConfiguration YAML file that defines the encryption provider (e.g., aescbc) and resources to encrypt. This flag enables encryption at rest for Kubernetes secrets and other API data stored in etcd.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    --encryption-config=/etc/kubernetes/enc/enc.yaml

    Why it's wrong here

    The kube-apiserver does not have a flag named --encryption-config; the correct flag is --encryption-provider-config. Passing a nonexistent flag would either cause the apiserver to abort with an unknown flag error or, in some versions, be silently ignored—in neither case would encryption be activated. The configuration file is supplied via the --encryption-provider-config flag.

  • ✗

    --enable-encryption

    Why it's wrong here

    There is no boolean switch called --enable-encryption on the kube-apiserver. Encryption at rest is not toggled with a simple on/off flag; the apiserver reads an encryption configuration file that defines the exact providers and resources to encrypt. Without the --encryption-provider-config flag, the apiserver will run without any at-rest encryption, regardless of any --enable-encryption attempt.

  • ✗

    --encryption-provider=aescbc

    Why it's wrong here

    The --encryption-provider flag does not exist; provider selection is not made from the command line. Instead, the --encryption-provider-config flag points to a YAML file whose providers list contains entries like identity, aescbc, and secretbox, along with corresponding keys. Passing aescbc as a direct flag would be rejected by the apiserver as an unknown flag and would not configure any encryption.

  • ✓

    --encryption-provider-config=/etc/kubernetes/enc/enc.yaml

    Why this is correct

    This is the correct flag to enable encryption at rest in kube-apiserver. --encryption-provider-config expects the file path to a YAML configuration that lists the resources (such as secrets) and the ordered encryption providers (identity, aescbc, secretbox, etc.) with their keys. When this flag is set, the apiserver encrypts data written to etcd and decrypts it on reads, allowing transparent encryption of Kubernetes Secrets and other supported resources.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.