Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

To encrypt secrets at rest in Kubernetes, an administrator configures an EncryptionConfiguration. What is the correct flag to pass to the kube-apiserver to use this configuration?

⚠ Common exam trap

Many exam-takers confuse the flag name with similar-sounding options like `--encryption-config` or `--encryption-key`, or mistakenly think encryption at rest is enabled via a Kubernetes feature gate (`--feature-gates=EncryptionAtRest=true`). In reality, Kubernetes secret encryption at rest requires an EncryptionConfiguration YAML file specified via the `--encryption-provider-config` flag on the kube-apiserver. The feature gate approach is not valid; the correct mechanism is the dedicated configuration file and flag.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

--encryption-provider-config=/path/to/config.yaml

The `--encryption-provider-config` flag is the exact command-line option that the kube-apiserver expects to locate the EncryptionConfiguration YAML file. This flag tells the API server to read the configuration that defines which encryption providers (e.g., `aescbc`, `secretbox`) to use for encrypting Kubernetes secrets at rest in etcd.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    --encryption-provider-config=/path/to/config.yaml

    Why this is correct

    The `--encryption-provider-config` flag points the kube-apiserver to an EncryptionConfiguration YAML file that defines which providers (like `aescbc`, `aesgcm`, or `secretbox`) to use for encrypting Secrets and other resources at rest. The file also holds the actual encryption keys under each provider and specifies the order in which providers are attempted for throttling and decryption. Without this flag, Kubernetes stores Secrets in etcd as plaintext, so this is the standard way to enable encryption.

  • ✗

    --feature-gates=EncryptionAtRest=true

    Why it's wrong here

    Encryption at rest is not controlled by a feature gate; the `--feature-gates` flag toggles alpha/beta features, not persistent security configurations. Even if an `EncryptionAtRest` gate existed, it would only activate code paths, but it would not supply the required provider definitions, key material, or resource list. The kube-apiserver must be given an EncryptionConfiguration file via `--encryption-provider-config` to actually encrypt data before writing to etcd, so merely setting this gate does nothing.

  • ✗

    --encryption-key=/path/to/config.yaml

    Why it's wrong here

    The kube-apiserver has no `--encryption-key` flag; encryption keys are never passed as a simple file path or command-line argument. Instead, keys (e.g., a base64-encoded 32-byte secret for `aescbc`) are embedded inside the `providers` section of the EncryptionConfiguration YAML, and each provider block references its own key. Passing only a key file would give the apiserver no information about which resources to encrypt, which provider algorithm to use, or how to handle multiple keys for rotation, so the command fails as an invalid flag.

  • ✗

    --encryption-config=/path/to/config.yaml

    Why it's wrong here

    There is no `--encryption-config` flag in kube-apiserver; the actual flag name is longer and more explicit: `--encryption-provider-config`. This misconception likely arises because users remember the concept of an 'encryption config' file, but the apiserver expects a provider-specific configuration that maps resources to encryption providers and key sets. Using the shortened name would cause the apiserver to exit with an "unknown flag" error, so it is not a valid alternative.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.