An administrator needs to enforce the restricted Pod Security Standard on a namespace 'secure-ns'. Which kubectl command should they use?
Labelling the namespace with the enforce label makes the Pod Security admission controller reject any pod violating the restricted profile at creation time. This satisfies the requirement to enforce, rather than merely warn or audit, the restricted standard namespace-wide.
Why this answer
The Pod Security Standards (PSS) are enforced via labels on namespaces, using the key `pod-security.kubernetes.io/enforce` with the value `restricted`. This instructs the built-in Pod Security Admission controller to reject any pod that violates the restricted profile in the `secure-ns` namespace.
Exam trap
The trap here is that candidates confuse labels with annotations or think that the old `PodSecurityPolicy` API is still the correct mechanism, but the CKS exam tests the modern Pod Security Standards via namespace labels.
How to eliminate wrong answers
Option B is wrong because `security=restricted` is not a recognized label for Pod Security Standards; the correct label key is `pod-security.kubernetes.io/enforce`. Option C is wrong because `PodSecurityPolicy` (PSP) is deprecated and removed since Kubernetes v1.25, and the command `kubectl create podsecuritypolicy` is not the correct way to enforce the restricted standard; PSS uses admission controller labels, not PSP objects. Option D is wrong because `kubectl annotate` uses annotations, not labels, and the Pod Security Admission controller specifically reads labels (not annotations) to determine the enforcement level.