CKS Minimize Microservice Vulnerabilities Practice Question
An administrator wants to enforce that all containers in a Kubernetes cluster run as non-root and have read-only root filesystems using OPA/Gatekeeper. Which two resources must be created?
⚠ Common exam trap
CNCF/CKS often tests whether you understand that OPA/Gatekeeper uses ConstraintTemplates and Constraints as the policy resources, not the underlying webhook configurations or legacy PodSecurityPolicy objects.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ConstraintTemplate and Constraint
OPA/Gatekeeper enforces policies via the Constraint Framework, which requires two resources: a ConstraintTemplate (defining the policy logic in Rego) and a Constraint (applying the template to specific resources). Together, they allow you to require containers run as non-root and have read-only root filesystems by evaluating admission requests against the defined rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
NetworkPolicy and RoleBinding
Why it's wrong here
NetworkPolicy and RoleBinding do not influence the pod admission decision. NetworkPolicy is a namespaced resource that filters east-west traffic between pods via selectors, while RoleBinding grants RBAC permissions to subjects like users or ServiceAccounts. Neither can inspect or reject a Pod's securityContext, Linux capabilities, or other container-level fields at creation time. Gatekeeper policies are expressed as OPA ConstraintTemplates and Constraints, which run in the admission webhook phase, not as network or RBAC objects.
- ✗
PodSecurityPolicy and ClusterRole
Why it's wrong here
PodSecurityPolicy (PSP) was a built-in admission controller that enforced pod security prerequisites, but it has been deprecated and removed in Kubernetes v1.25, and it is not part of OPA Gatekeeper. Gatekeeper requires a ConstraintTemplate containing Rego logic to validate resource fields and a Constraint to apply that logic to specific kinds and scopes. ClusterRole only defines RBAC authorization rules and cannot enforce security constraints on container runtime settings. Admin-created Gatekeeper policies rely on custom resource definitions, not PSP or RBAC objects.
- ✗
ValidatingWebhookConfiguration and MutatingWebhookConfiguration
Why it's wrong here
ValidatingWebhookConfiguration and MutatingWebhookConfiguration are the Kubernetes plumbing that routes admission requests to a webhook server; they do not contain policy logic. When Gatekeeper is deployed via its manifests or Helm chart, it automatically creates a ValidatingWebhookConfiguration that points to its admission service, so an administrator does not author these to define constraints. Writing policies with Gatekeeper means authoring a ConstraintTemplate (which embeds Rego) and a Constraint (which sets enforcement parameters). These webhook configuration objects are an implementation detail, not the policy definition interface.
- ✓
ConstraintTemplate and Constraint
Why this is correct
ConstraintTemplate and Constraint are the correct custom resources in the OPA Gatekeeper framework. A ConstraintTemplate defines the rego policy, including the violation message and the parameters schema, while a Constraint instantiates that template with concrete values such as 'required labels' or 'forbidden capabilities'. This two-layer model allows one policy to be reused across many targets with different parameters. Together they implement a declarative admission policy that can reject any Kubernetes resource at admission time.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.