Courseiva
mediumMultiple Choice

CKS Practice Question: Ensure that no service account in the…

An administrator wants to ensure that no service account in the 'development' namespace has cluster-admin privileges. Which command should be used to identify such bindings?

⚠ Common exam trap

Candidates often confuse `RoleBindings` (namespace-scoped) with `ClusterRoleBindings` (cluster-scoped), assuming that `RoleBindings` can grant cluster-admin privileges, or they mistakenly think listing service accounts or describing the ClusterRole itself will reveal the bindings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl get clusterrolebindings -o yaml | grep -B 10 namespace: development

`ClusterRoleBindings` are cluster-scoped resources that grant permissions across all namespaces, including the `development` namespace. By piping the YAML output through `grep -B 10 namespace: development`, you can identify which `ClusterRoleBinding` references a service account in the `development` namespace, revealing any binding that could grant cluster-admin privileges to that namespace's service accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl get serviceaccounts -n development

    Why it's wrong here

    This command simply lists the ServiceAccount objects in the development namespace. ServiceAccounts are just identities; permissions are granted through RoleBindings and ClusterRoleBindings. The output reveals nothing about which roles or bindings those accounts have, so an administrator auditing cluster-admin grants cannot detect the cluster-wide ClusterRoleBinding that ties a service account in that namespace to the role.

  • ✓

    kubectl get clusterrolebindings -o yaml | grep -B 10 namespace: development

    Why this is correct

    This is the correct approach because ClusterRoleBindings are the only mechanism that can grant a cluster-scoped role like cluster-admin to subjects, including ServiceAccounts. The YAML output includes each binding's subjects, and the -B 10 context around 'namespace: development' reveals bindings whose subjects reference a ServiceAccount in that namespace. This surfaces the specific ClusterRoleBinding and its roleRef, allowing the admin to see exactly who is bound to cluster-admin or any other cluster role. It is a practical grep-based audit even though it may also match unrelated namespaces in other fields.

  • ✗

    kubectl get rolebindings -n development --all-namespaces

    Why it's wrong here

    The --all-namespaces flag overrides -n development, so this lists RoleBindings in every namespace, not just development. More fundamentally, a RoleBinding can only grant permissions within its own namespace; even if it references the cluster-admin ClusterRole, the effective permissions are scoped to that namespace and do not confer cluster-wide admin rights. Therefore inspecting RoleBindings cannot identify ServiceAccounts that hold the actual cluster-admin cluster role.

  • ✗

    kubectl describe clusterrole cluster-admin

    Why it's wrong here

    This command describes the cluster-admin ClusterRole object, showing its aggregated rules like '*.*' for all verbs. It does not include any subject or binding information because roles and bindings are separate RBAC resources. To discover which users, groups, or ServiceAccounts are bound to cluster-admin, you must inspect ClusterRoleBindings that have roleRef.name: cluster-admin, such as the default binding for system:masters. Without that step, the audit is incomplete.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.