Courseiva
mediumMatching

CKS Practice Question: Match each Kubernetes certificate type to its…

Match each Kubernetes certificate type to its usage.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Used by kubelet to serve the kubelet API (e.g., exec, logs)

Used by kubelet to authenticate to the API server

Used by the API server to serve HTTPS endpoints

Used to sign service account tokens so they can be verified

Used by an administrator to authenticate to the cluster with full privileges

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

API server serving certificate: Encrypts communication between clients and the API server

Two common certificate types in Kubernetes are the API server serving certificate (used for HTTPS encryption) and the kubelet client certificate (used for kubelet authentication to the API server). A common confusion is swapping their purposes: the API server serving certificate does not authenticate the API server to the kubelet, and the kubelet client certificate does not encrypt inter-node communication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    API server serving certificate: Encrypts communication between clients and the API server

    Why this is correct

    The API server serving certificate is the X.509 certificate configured via --tls-cert-file and --tls-private-key-file on the kube-apiserver. It is presented by the API server to every HTTPS client, including kubectl, kubelets, controllers, and external agents, establishing an encrypted TLS channel and proving the API server's identity to the client. This certificate does not secure outbound connections; it only protects inbound traffic to the API server.

  • ✓

    Kubelet client certificate: Authenticates the kubelet to the API server

    Why this is correct

    The kubelet client certificate is part of the kubelet's kubeconfig and is presented by the kubelet when it makes API requests to the API server, such as when registering the node, reporting status, or sending pod updates. This certificate enables mutual TLS authentication, allowing the API server to verify the kubelet's identity from the certificate's Common Name (CN) and Organization (O), which Kubernetes maps to a username and groups for RBAC decisions.

  • ✗

    API server serving certificate: Authenticates the API server to the kubelet

    Why it's wrong here

    This statement confuses the API server serving certificate with the API server's client certificate. When the API server connects to a kubelet's HTTPS endpoint (for example, for logs or exec), it authenticates using a separate `--kubelet-client-certificate`, not the serving certificate. The kubelet verifies the API server by checking that this client certificate chains to its configured certificate authority; the serving certificate is only presented to inbound clients of the API server, so it cannot authenticate the API server to the kubelet.

  • ✗

    Kubelet client certificate: Encrypts communication between nodes

    Why it's wrong here

    The kubelet client certificate is used exclusively for outbound authentication from the kubelet to the API server; it does not directly encrypt any traffic. Encryption between nodes is achieved through TLS sessions established with the appropriate certificates on each side—for instance, the kubelet's server certificate encrypts connections to the kubelet's HTTPS endpoint, while the API server's client certificate protects the API server's outbound requests. Node-to-node encryption is therefore a session-level property, not an inherent function of the kubelet client certificate alone.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.