Courseiva
mediumMatching

CKS Practice Question: Match each Kubernetes command to its function…

Match each Kubernetes command to its function related to security.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Check whether an action is allowed for a user or service account

Approve a certificate signing request (CSR)

Run a temporary interactive pod for troubleshooting

Create a secret from literals, files, or directories

Apply a PodSecurityPolicy configuration (deprecated)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl auth can-i: Check if a user can perform a specific action

The correct matches are: 'kubectl auth can-i' checks permissions, 'kubectl certificate approve' handles CSRs, 'kubectl describe clusterrole' shows role details, and 'kubectl create serviceaccount' creates service accounts. Common confusions include mixing the functions of permission checking and resource creation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kubectl auth can-i: Check if a user can perform a specific action

    Why this is correct

    kubectl auth can-i performs an authorization check against the Kubernetes API, answering whether a user (or service account) has permission to execute a specific verb on a resource, e.g., 'kubectl auth can-i create pods'. It constructs a SubjectAccessReview (or SelfSubjectAccessReview for the current user) and reports the decision without actually making any changes. The --as flag allows impersonating another identity to test their permissions, making it a standard diagnostic tool for RBAC issues.

  • ✓

    kubectl certificate approve: Approve a certificate signing request (CSR)

    Why this is correct

    kubectl certificate approve is used to approve a CertificateSigningRequest (CSR) object, which authorizes the Kubernetes controller-manager's signer to issue a signed certificate to the requester. Approving requires the caller to have permission on the 'certificatesigningrequests/approval' subresource, typically via the 'system:certificates.k8s.io:certificatesigningrequests/approver' role. This command does not generate certificates itself; it only changes the CSR status from pending to approved.

  • ✓

    kubectl describe clusterrole: Display detailed information about a ClusterRole

    Why this is correct

    kubectl describe clusterrole retrieves a ClusterRole object in a human-readable format, showing its metadata, labels, annotations, and most importantly, the aggregated rule sets: the API groups, resources, resource names, and verbs allowed. Unlike 'kubectl get clusterrole' which only lists role names, describe expands the rules and shows details such as non-resource URL paths and whether resource names are restricted. This helps administrators audit what permissions a cluster-scoped role actually grants.

  • ✓

    kubectl create serviceaccount: Create a new service account

    Why this is correct

    kubectl create serviceaccount creates a ServiceAccount resource in a specified namespace, enabling workloads to identify themselves to the API server. In Kubernetes v1.22+ with legacy tokens, it may also create a corresponding secret; however, modern deployments typically rely on projected service account tokens for pod authentication. The command is part of the 'kubectl create' family, distinct from RBAC authorization commands, and is commonly used before binding roles to run pods with specific permissions.

  • ✗

    kubectl auth can-i: Create a new service account

    Why it's wrong here

    This is incorrect because 'kubectl auth can-i' only evaluates and queries authorization rules; it never creates or modifies any Kubernetes objects. Creating a service account is a write operation performed by 'kubectl create serviceaccount', which constructs the ServiceAccount API resource. The 'can-i' command would be used to first check whether the current user has create permission on serviceaccounts, but it does not perform the creation itself.

  • ✗

    kubectl certificate approve: Display details of a ClusterRole

    Why it's wrong here

    This is incorrect because 'kubectl certificate approve' applies to CertificateSigningRequest resources, changing their status to approved for certificate issuance, whereas displaying details of a ClusterRole is a read operation performed by 'kubectl describe clusterrole'. The two commands operate on entirely different API groups: certificates.k8s.io vs rbac.authorization.k8s.io. Confusing them mixes write operations in certificate management with read-only RBAC inspection, which would not yield any role details.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.