CKS System Hardening Practice Question
An administrator wants to enforce the Pod Security Standard 'restricted' for all pods in the 'secure' namespace. Which kubectl command correctly enables the PodSecurity admission controller for that namespace?
⚠ Common exam trap
Candidates often confuse labels with annotations or mixing up the `enforce`, `audit`, and `warn` modes, leading candidates to choose an annotation or the wrong label key for enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl label ns secure pod-security.kubernetes.io/enforce=restricted
The Pod Security Standards are enforced on namespaces using the `pod-security.kubernetes.io/enforce` label set to the desired policy level (e.g., `restricted`). The `kubectl label` command applies this label to the namespace, which triggers the PodSecurity admission controller to enforce the restricted policy on all pods created in that namespace.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl annotate ns secure pod-security.kubernetes.io/enforce=restricted
Why it's wrong here
Using `kubectl annotate` is incorrect because Pod Security Admission (PSA) reads labels, not annotations, to determine the enforcement policy. The kube-apiserver's admission plug-in specifically looks for the `pod-security.kubernetes.io/enforce` label key on the namespace object. Even if an annotation uses the identical key, it is ignored for PSA decisions, so this command would produce no enforcement effect. Moreover, annotations are for arbitrary metadata, not for admission control configuration.
- ✓
kubectl label ns secure pod-security.kubernetes.io/enforce=restricted
Why this is correct
This is the correct command because `kubectl label` sets the `pod-security.kubernetes.io/enforce` label on the namespace, which is exactly what the Pod Security Admission plug-in reads to decide the policy level and mode. Setting its value to `restricted` puts the namespace in enforce mode with the most stringent policy standard, so any pod that does not meet the restricted profile's security requirements will be rejected by the admission controller. Labels are the designated API mechanism for namespace-level PSA configuration, and this key is case-sensitive and must be spelled exactly as shown.
- ✗
kubectl label ns secure pod-security.kubernetes.io/enforce-version=restricted
Why it's wrong here
The label `pod-security.kubernetes.io/enforce-version` is meant to pin the Kubernetes version of the Pod Security Standards being applied, such as `v1.29`, not to specify a policy level like `restricted`. PSA expects the value of an `*-version` label to be a valid version string; using `restricted` is invalid and will be ignored. Furthermore, setting the version label alone does not enable enforcement—you must separately set the `pod-security.kubernetes.io/enforce` label with a policy level. Thus this command neither enforces the restricted policy nor configures a proper version pin.
- ✗
kubectl label ns secure pod-security.kubernetes.io/audit=restricted
Why it's wrong here
The `pod-security.kubernetes.io/audit` label puts the namespace into audit mode, meaning the admission controller will log any pods that violate the restricted policy to the Kubernetes audit log, but it will not block or reject those pods. Since the administrator specifically wants to enforce the standard, this command fails to provide the intended behavior. Enforcement requires the separate label `pod-security.kubernetes.io/enforce`; only that label causes the admission controller to deny non-compliant pod creation. Audit mode is useful for testing policy impact before enforcement, but it is not a substitute for enforcement.
Go deeper
Related to this question
Learn chapter
Microservice Vulnerabilities: Pod Security Standards
Key term
Pod Security Admission
Pod Security Admission is a Kubernetes feature that enforces security standards on pods at creation time to prevent running containers with dangerous privileges.
Key term
Node Restriction
A Kubernetes admission controller that limits what a kubelet can modify on its own node to prevent privilege escalation and unauthorized access.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.