CKS Minimize Microservice Vulnerabilities Practice Question
To encrypt secrets at rest in Kubernetes, an administrator configures an EncryptionConfiguration. What is the correct flag to pass to the kube-apiserver to use this configuration?
⚠ Common exam trap
Many exam-takers confuse the flag name with similar-sounding options like `--encryption-config` or `--encryption-key`, or mistakenly think encryption at rest is enabled via a Kubernetes feature gate (`--feature-gates=EncryptionAtRest=true`). In reality, Kubernetes secret encryption at rest requires an EncryptionConfiguration YAML file specified via the `--encryption-provider-config` flag on the kube-apiserver. The feature gate approach is not valid; the correct mechanism is the dedicated configuration file and flag.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--encryption-provider-config=/path/to/config.yaml
The `--encryption-provider-config` flag is the exact command-line option that the kube-apiserver expects to locate the EncryptionConfiguration YAML file. This flag tells the API server to read the configuration that defines which encryption providers (e.g., `aescbc`, `secretbox`) to use for encrypting Kubernetes secrets at rest in etcd.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
--encryption-provider-config=/path/to/config.yaml
Why this is correct
The `--encryption-provider-config` flag points the kube-apiserver to an EncryptionConfiguration YAML file that defines which providers (like `aescbc`, `aesgcm`, or `secretbox`) to use for encrypting Secrets and other resources at rest. The file also holds the actual encryption keys under each provider and specifies the order in which providers are attempted for throttling and decryption. Without this flag, Kubernetes stores Secrets in etcd as plaintext, so this is the standard way to enable encryption.
- ✗
--feature-gates=EncryptionAtRest=true
Why it's wrong here
Encryption at rest is not controlled by a feature gate; the `--feature-gates` flag toggles alpha/beta features, not persistent security configurations. Even if an `EncryptionAtRest` gate existed, it would only activate code paths, but it would not supply the required provider definitions, key material, or resource list. The kube-apiserver must be given an EncryptionConfiguration file via `--encryption-provider-config` to actually encrypt data before writing to etcd, so merely setting this gate does nothing.
- ✗
--encryption-key=/path/to/config.yaml
Why it's wrong here
The kube-apiserver has no `--encryption-key` flag; encryption keys are never passed as a simple file path or command-line argument. Instead, keys (e.g., a base64-encoded 32-byte secret for `aescbc`) are embedded inside the `providers` section of the EncryptionConfiguration YAML, and each provider block references its own key. Passing only a key file would give the apiserver no information about which resources to encrypt, which provider algorithm to use, or how to handle multiple keys for rotation, so the command fails as an invalid flag.
- ✗
--encryption-config=/path/to/config.yaml
Why it's wrong here
There is no `--encryption-config` flag in kube-apiserver; the actual flag name is longer and more explicit: `--encryption-provider-config`. This misconception likely arises because users remember the concept of an 'encryption config' file, but the apiserver expects a provider-specific configuration that maps resources to encryption providers and key sets. Using the shortened name would cause the apiserver to exit with an "unknown flag" error, so it is not a valid alternative.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.