mediumMultiple Choice
CKS Practice Question: An administrator runs kube-bench on a cluster…
An administrator runs kube-bench on a cluster node and receives failures for CIS benchmark checks related to kubelet configuration. Which kubelet flag should be set to ensure that kernel defaults are not used when they might be insecure?
⚠ Common exam trap
Many exam-takers confuse `--protect-kernel-defaults` with other kubelet security flags like `--read-only-port` or `--anonymous-auth`, or mistakenly think `--kubelet-extra-args` is a direct kubelet flag, when in fact it is a kubeadm configuration option and not a solution for kernel default protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--protect-kernel-defaults
The `--protect-kernel-defaults` kubelet flag ensures that the kubelet will not use insecure kernel defaults by enforcing that certain sysctl settings (e.g., `kernel.panic`, `vm.overcommit_memory`) are set to secure values. If these kernel parameters are not explicitly configured to safe values, the kubelet will fail to start, preventing the node from running with potentially insecure kernel defaults. This directly addresses CIS benchmark checks that require hardening of the kubelet's interaction with the host kernel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
--protect-kernel-defaults
Why this is correct
--protect-kernel-defaults makes the kubelet refuse to start when kernel parameters such as sysctl settings differ from secure values, rather than silently accepting insecure kernel defaults. This directly satisfies the CIS benchmark checks failing on kubelet configuration.
- ✗
--read-only-port=0
Why it's wrong here
--read-only-port=0 disables the unauthenticated read-only kubelet port, addressing a different CIS control about anonymous access. It is tempting because it hardens the kubelet, but the check for refusing insecure kernel defaults is satisfied by --protect-kernel-defaults=true, which makes the kubelet fail when sysctl values diverge from secure baselines.
- ✗
--anonymous-auth=false
Why it's wrong here
--anonymous-auth=false blocks unauthenticated requests to the kubelet API, which is a separate CIS recommendation. It is tempting because it is a genuine kubelet hardening flag, but the control about not inheriting insecure kernel defaults requires --protect-kernel-defaults=true, which enforces secure sysctl settings at startup.
- ✗
--kubelet-extra-args
Why it's wrong here
--kubelet-extra-args is not a kubelet flag; it is a kubeadm NodeRegistration option that appends arguments to the generated kubelet invocation. It is tempting because it does inject kubelet settings, but CIS checks target the kubelet's own flags, such as --protect-kernel-defaults, which must be set directly.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator runs `kube-bench` and sees that the check 'Ensure that the --protect-kernel-defaults flag is set to true' has failed. Which component does this check apply to?
medium- A.etcd
- B.API server
- ✓ C.Kubelet
- D.Controller manager
Why C: The `--protect-kernel-defaults` flag is a kubelet-specific security option that ensures the kubelet does not modify kernel parameters that could weaken node security. When set to true, it enforces that the kubelet respects kernel defaults, preventing privilege escalation via sysctl overrides. This check is part of the CIS Benchmark for the kubelet component, not for etcd, the API server, or the controller manager.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.