mediumMultiple Choice
CKS Practice Question: An administrator runs kube-bench and receives a…
An administrator runs kube-bench and receives a failing result for CIS control 1.1.1. What does this control typically check?
⚠ Common exam trap
CNCF often tests candidates' ability to map CIS control numbers to their exact checks, so the trap here is that candidates confuse control 1.1.1 (file permissions) with other common API server hardening controls like TLS, audit logging, or authentication settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
That the API server pod specification file permissions are set to 644 or more restrictive
CIS control 1.1.1 specifically checks that the API server pod specification file (typically /etc/kubernetes/manifests/kube-apiserver.yaml) has permissions set to 644 or more restrictive (e.g., 600 or 640). This ensures that only authorized users (root or the kube-apiserver process) can read or modify the file, preventing unauthorized changes to critical API server configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
That the API server pod specification file permissions are set to 644 or more restrictive
Why this is correct
The failing kube-bench result corresponds to control 1.1.1, which checks that the API server pod specification file (typically /etc/kubernetes/manifests/kube-apiserver.yaml) has permissions set to 644 or more restrictive. If this file is group- or world-writable, a local attacker could modify the manifest to inject malicious flags, replace certificates, or alter the API server's configuration without authentication. Kube-bench flags this as a failure when the file mode allows write access beyond the owner. This is exactly the check being reported.
- ✗
That etcd is using TLS
Why it's wrong here
While enabling TLS for etcd is a valid CIS hardening measure, it is evaluated under a separate kube-bench control (e.g., 2.2 for client communication or 2.3 for peer communication). That control verifies that flags such as --cert-file, --key-file, and --peer-cert-file are correctly set, not the permissions of the API server manifest. The failure described in the question is specifically about the API server pod specification file permissions, so the etcd TLS configuration is a different control and cannot be the correct answer.
- ✗
That the API server audit log path is configured
Why it's wrong here
Configuring the API server audit log path is a distinct kube-bench check (e.g., 1.2.22 or related controls) that ensures the --audit-log-path flag is set to a secure location. This is crucial for detecting and investigating suspicious activities, but it operates entirely outside the filesystem permissions of the static pod manifest. The reported failure concerns the file mode of /etc/kubernetes/manifests/kube-apiserver.yaml, not whether audit logging is enabled. Therefore, this option addresses an unrelated control.
- ✗
That anonymous authentication is disabled on the API server
Why it's wrong here
Disabling anonymous authentication is another separate kube-bench control (typically 1.2.1) that checks the --anonymous-auth=false flag on the API server. This setting prevents unauthenticated requests from reaching the cluster, but it is a runtime configuration flag, not a file permission on the pod specification. The failure in question is about the permissions of the manifest file itself, which is a static filesystem check. Anonymous auth and file permissions are both important, but kube-bench evaluates them independently, so this answer does not match the specific failing control.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.