mediumMultiple Choice
CKS Practice Question: An administrator runs 'kubectl auth can-i --list…
An administrator runs 'kubectl auth can-i --list --as=system:serviceaccount:ns1:my-sa' and sees that the service account has 'create pods' permission via a RoleBinding. Which command can be used to delete that RoleBinding?
⚠ Common exam trap
CNCF often tests the misconception that deleting the role or the service account is equivalent to removing the permission, but the correct action is to delete the RoleBinding that grants the permission.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl delete rolebinding <binding-name> -n ns1
The `kubectl auth can-i --list` output shows that the service account `my-sa` has `create pods` permission via a RoleBinding. To remove that permission, you must delete the RoleBinding object itself, not the service account or the role (unless the role is exclusively used by this binding). Option C correctly uses `kubectl delete rolebinding` with the specific binding name and namespace to revoke the RBAC grant.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl delete serviceaccount my-sa -n ns1
Why it's wrong here
The `kubectl delete serviceaccount my-sa -n ns1` command removes the ServiceAccount object itself, not any RoleBindings that reference it. A RoleBinding exists independently; even if its subject (the SA) is deleted, the binding object remains in etcd and continues to appear in RBAC queries with an unresolved subject reference. To revoke the permissions that the binding grants, you must delete the RoleBinding resource, not the ServiceAccount.
- ✗
kubectl delete role <role-name> -n ns1
Why it's wrong here
Deleting the Role with `kubectl delete role <role-name> -n ns1` only removes the Role definition, leaving the RoleBinding object untouched. The RoleBinding still exists but now points to a non-existent Role, which causes it to grant no permissions (since the referenced Role is gone), yet the binding itself remains as a stale resource. To properly remove the binding and its association, delete the RoleBinding directly; deleting the Role alone does not clean up the RoleBinding.
- ✓
kubectl delete rolebinding <binding-name> -n ns1
Why this is correct
The `kubectl delete rolebinding <binding-name> -n ns1` command targets the exact RBAC resource that connects a Role to subjects such as users, groups, or ServiceAccounts. Because RoleBindings are namespaced, specifying the namespace ensures you're deleting the correct binding for that namespace. This is the definitive way to revoke the permissions that the binding granted, as it removes the association object entirely.
- ✗
kubectl delete clusterrolebinding <binding-name>
Why it's wrong here
The `kubectl delete clusterrolebinding <binding-name>` command is used to delete cluster-scoped bindings, but if the binding in question is a RoleBinding, it is namespace-scoped and cannot be removed by this command. Even if you provide the same name, deleting a ClusterRoleBinding with that name will not affect a RoleBinding with the same name in the namespace; they are separate resources in different scopes. To delete the RoleBinding, you must use `kubectl delete rolebinding` and include the `-n` flag with the correct namespace.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.