Courseiva
System Hardening →hardMultiple Choice

CKS System Hardening Practice Question

Network Topology
$ kube-apiserveradmission-control=PodSecurityenable-admission-plugins=AlwaysPullImagesRefer to the exhibit.```

Given the exhibit, what will happen when a user creates a pod with an image from an untrusted registry?

⚠ Common exam trap

CNCF often tests the misconception that Kubernetes has a built-in 'untrusted registry' blocker, when in reality it requires explicit admission control or runtime configuration to enforce such policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The pod is created and the image is pulled

By default, Kubernetes does not enforce any restrictions on image registries. The kubelet will attempt to pull the image from any registry, including untrusted ones, unless an admission controller like ImagePolicyWebhook or a runtime-specific policy (e.g., containerd's `untrusted_workload` mode) is explicitly configured. In this scenario, no such policy is mentioned, so the pod is created and the image is pulled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The pod is rejected by NodeRestriction admission

    Why it's wrong here

    NodeRestriction admission controller is an alpha/beta feature that constrains the kubelet's ability to modify Node and Pod objects, primarily by enforcing that the kubelet can only update its own Node and the pods bound to it. It applies only to kubelet API requests, not to normal user authentication when creating a pod, and it has no logic to inspect image names or registries. Therefore it cannot reject a user's pod creation.

  • ✗

    The pod is rejected by PodSecurity admission

    Why it's wrong here

    PodSecurity admission (the successor to PodSecurityPolicy) evaluates the pod's security context against a policy level of privileged, baseline, or restricted, checking options like privileged containers, Linux capabilities, host namespaces, and allowed volume types. It does not parse the image reference, registry host, or digest, nor does it enforce any policy on which registries are allowed. A pod with an unusual registry would still pass PodSecurity because that is outside its scope.

  • ✓

    The pod is created and the image is pulled

    Why this is correct

    The AlwaysPullImages admission controller mutates each new pod's containers, setting imagePullPolicy to Always, which forces the kubelet to pull the image from the registry at every pod start rather than using local cache. This mutation is a validation-type operation that does not reject the pod; the pod is admitted and scheduled. The kubelet then performs an image pull from the specified registry, and since no admission controller or runtime configuration in the default chain blocks untrusted registries, the pull succeeds and the pod runs.

  • ✗

    The pod is created but the image is not pulled because it's untrusted

    Why it's wrong here

    There is no built-in mechanism in the standard Kubernetes admission chain that checks whether an image registry is 'trusted' or 'untrusted'. The kubelet simply attempts to pull the image based on the imagePullPolicy; if the registry is reachable and the image exists, it will be pulled. Blocking untrusted registries requires explicit supply-chain security layers, such as a validating admission policy, an image policy webhook, or container runtime signature verification like Container Image Signing, none of which are indicated in the exhibit.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.