mediumMultiple Choice
CKS Practice Question: To enforce Pod Security Standards at the…
To enforce Pod Security Standards at the namespace level, which admission plugin must be enabled on the API server?
⚠ Common exam trap
CNCF often tests the distinction between the deprecated PodSecurityPolicy (PSP) and the current PodSecurity admission plugin, leading candidates to mistakenly select PSP because they recall 'Pod Security' in the name, but PSP is no longer available in recent Kubernetes versions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PodSecurity
Pod Security Standards (PSS) are enforced at the namespace level using the PodSecurity admission plugin, which was introduced in Kubernetes v1.23 and graduated to stable in v1.25. This plugin evaluates pods against the predefined security levels (privileged, baseline, restricted) based on labels on the namespace, replacing the deprecated PodSecurityPolicy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SecurityContextDeny
Why it's wrong here
SecurityContextDeny is a legacy admission controller, removed in Kubernetes v1.27, that rejected any Pod whose securityContext or container-level fields such as privileged, runAsUser, or capabilities were set. It operates cluster-wide and not through per-namespace labels, so it cannot enforce the Pod Security Standards' Baseline or Restricted profiles granularly. Choosing it would block legitimate compliant Pods and is not the standard enforcement mechanism.
- ✗
NodeRestriction
Why it's wrong here
NodeRestriction is an admission controller that limits the permissions of kubelet credentials: a kubelet can only modify its own Node object and Pods bound to that Node, and cannot change Node labels or taints outside an allowed set. It has no knowledge of securityContext, capabilities, or the Pod Security Standards; it only narrows what authenticated kubelets may do to API objects. It is therefore about kubelet authorization, not namespace-level pod security.
- ✗
PodSecurityPolicy
Why it's wrong here
PodSecurityPolicy (PSP) was a policy/v1beta1 admission mechanism that allowed cluster admins to define fine-grained conditions such as allowed privilege escalation, required seccomp profiles, and host namespace usage. It was deprecated in Kubernetes 1.21 and removed in 1.25, and it also required PSP objects to be created and bound via RBAC, rather than being driven by simple namespace labels. Since PSP is no longer available in current clusters, it cannot be used to enforce Pod Security Standards at the namespace level.
- ✓
PodSecurity
Why this is correct
PodSecurity is the built-in admission controller that enforces the three Pod Security Standards (privileged, baseline, restricted) using namespace labels such as pod-security.kubernetes.io/enforce=restricted. During Pod creation and update, it checks the effective policy derived from the namespace labels and rejects non-compliant Pods, while supporting warn, audit, and enforce modes for gradual rollout. It is the current mechanism that replaces the deprecated PodSecurityPolicy and enforces PSS at the namespace level.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Policy Enforcement and Admission Controllers
Key term
Pod Security Admission
Pod Security Admission is a Kubernetes feature that enforces security standards on pods at creation time to prevent running containers with dangerous privileges.
Key term
Admission Controllers
Admission controllers are plugins that intercept and process requests to the Kubernetes API server after authentication and authorization, but before the request is persisted, allowing policies to be enforced on objects being created, modified, or deleted.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.