mediumMultiple Choice
CKS Practice Question: An administrator creates an…
An administrator creates an EncryptionConfiguration with aescbc and saves it to /etc/kubernetes/enc/enc.yaml. Which flag must be added to the kube-apiserver to enable encryption at rest?
⚠ Common exam trap
Many candidates confuse the valid `--encryption-provider-config` flag with similar-sounding but invalid flags like `--encryption-config` or `--encryption-provider`, or assume a simple `--enable-encryption` toggle exists, when in reality encryption at rest requires a detailed configuration file.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--encryption-provider-config=/etc/kubernetes/enc/enc.yaml
The kube-apiserver requires the `--encryption-provider-config` flag to specify the path to the EncryptionConfiguration YAML file that defines the encryption provider (e.g., aescbc) and resources to encrypt. This flag enables encryption at rest for Kubernetes secrets and other API data stored in etcd.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
--encryption-config=/etc/kubernetes/enc/enc.yaml
Why it's wrong here
The kube-apiserver does not have a flag named --encryption-config; the correct flag is --encryption-provider-config. Passing a nonexistent flag would either cause the apiserver to abort with an unknown flag error or, in some versions, be silently ignored—in neither case would encryption be activated. The configuration file is supplied via the --encryption-provider-config flag.
- ✗
--enable-encryption
Why it's wrong here
There is no boolean switch called --enable-encryption on the kube-apiserver. Encryption at rest is not toggled with a simple on/off flag; the apiserver reads an encryption configuration file that defines the exact providers and resources to encrypt. Without the --encryption-provider-config flag, the apiserver will run without any at-rest encryption, regardless of any --enable-encryption attempt.
- ✗
--encryption-provider=aescbc
Why it's wrong here
The --encryption-provider flag does not exist; provider selection is not made from the command line. Instead, the --encryption-provider-config flag points to a YAML file whose providers list contains entries like identity, aescbc, and secretbox, along with corresponding keys. Passing aescbc as a direct flag would be rejected by the apiserver as an unknown flag and would not configure any encryption.
- ✓
--encryption-provider-config=/etc/kubernetes/enc/enc.yaml
Why this is correct
This is the correct flag to enable encryption at rest in kube-apiserver. --encryption-provider-config expects the file path to a YAML configuration that lists the resources (such as secrets) and the ordered encryption providers (identity, aescbc, secretbox, etc.) with their keys. When this flag is set, the apiserver encrypts data written to etcd and decrypts it on reads, allowing transparent encryption of Kubernetes Secrets and other supported resources.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.