Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

An administrator wants to enforce that all containers in a Kubernetes cluster run as non-root and have read-only root filesystems using OPA/Gatekeeper. Which two resources must be created?

⚠ Common exam trap

CNCF/CKS often tests whether you understand that OPA/Gatekeeper uses ConstraintTemplates and Constraints as the policy resources, not the underlying webhook configurations or legacy PodSecurityPolicy objects.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ConstraintTemplate and Constraint

OPA/Gatekeeper enforces policies via the Constraint Framework, which requires two resources: a ConstraintTemplate (defining the policy logic in Rego) and a Constraint (applying the template to specific resources). Together, they allow you to require containers run as non-root and have read-only root filesystems by evaluating admission requests against the defined rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    NetworkPolicy and RoleBinding

    Why it's wrong here

    NetworkPolicy and RoleBinding do not influence the pod admission decision. NetworkPolicy is a namespaced resource that filters east-west traffic between pods via selectors, while RoleBinding grants RBAC permissions to subjects like users or ServiceAccounts. Neither can inspect or reject a Pod's securityContext, Linux capabilities, or other container-level fields at creation time. Gatekeeper policies are expressed as OPA ConstraintTemplates and Constraints, which run in the admission webhook phase, not as network or RBAC objects.

  • ✗

    PodSecurityPolicy and ClusterRole

    Why it's wrong here

    PodSecurityPolicy (PSP) was a built-in admission controller that enforced pod security prerequisites, but it has been deprecated and removed in Kubernetes v1.25, and it is not part of OPA Gatekeeper. Gatekeeper requires a ConstraintTemplate containing Rego logic to validate resource fields and a Constraint to apply that logic to specific kinds and scopes. ClusterRole only defines RBAC authorization rules and cannot enforce security constraints on container runtime settings. Admin-created Gatekeeper policies rely on custom resource definitions, not PSP or RBAC objects.

  • ✗

    ValidatingWebhookConfiguration and MutatingWebhookConfiguration

    Why it's wrong here

    ValidatingWebhookConfiguration and MutatingWebhookConfiguration are the Kubernetes plumbing that routes admission requests to a webhook server; they do not contain policy logic. When Gatekeeper is deployed via its manifests or Helm chart, it automatically creates a ValidatingWebhookConfiguration that points to its admission service, so an administrator does not author these to define constraints. Writing policies with Gatekeeper means authoring a ConstraintTemplate (which embeds Rego) and a Constraint (which sets enforcement parameters). These webhook configuration objects are an implementation detail, not the policy definition interface.

  • ✓

    ConstraintTemplate and Constraint

    Why this is correct

    ConstraintTemplate and Constraint are the correct custom resources in the OPA Gatekeeper framework. A ConstraintTemplate defines the rego policy, including the violation message and the parameters schema, while a Constraint instantiates that template with concrete values such as 'required labels' or 'forbidden capabilities'. This two-layer model allows one policy to be reused across many targets with different parameters. Together they implement a declarative admission policy that can reject any Kubernetes resource at admission time.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.