CKS Minimize Microservice Vulnerabilities Practice Question
Which admission controller is responsible for validating and mutating requests based on webhooks?
⚠ Common exam trap
The exam often tests the distinction between built-in admission controllers (like PodSecurityPolicy or ServiceAccount) and webhook-based controllers, expecting candidates to know that only ValidatingAdmissionWebhook and MutatingAdmissionWebhook rely on external HTTP callbacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ValidatingAdmissionWebhook and MutatingAdmissionWebhook
The ValidatingAdmissionWebhook and MutatingAdmissionWebhook admission controllers are specifically designed to intercept admission requests and call external webhooks to validate or mutate the request. MutatingAdmissionWebhook can modify the object (e.g., inject sidecar containers) before it is persisted, while ValidatingAdmissionWebhook only validates and can reject the request. These controllers are the only ones that delegate admission decisions to external HTTP callbacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ServiceAccount
Why it's wrong here
ServiceAccount is a built-in admission controller that automates service account creation and token injection, such as assigning the default service account to pods and projecting service account tokens into filesystems. It is not webhook-based and performs no external HTTP callbacks, so it cannot be responsible for custom validation or mutation via admission webhooks.
- ✗
PodSecurityPolicy
Why it's wrong here
PodSecurityPolicy (PSP) was a built-in admission controller that enforced pod security constraints like privileged mode and host namespaces, but it was deprecated in 1.21 and removed in 1.25, and it never used webhooks. It operated via static policy evaluation inside the kube-apiserver, not by calling external webhook servers, so it cannot be the required controller for webhook-driven validation and mutation.
- ✗
NodeRestriction
Why it's wrong here
NodeRestriction is an admission controller that restricts which Node objects a node credential can modify, enforcing API access limits for nodes such as denying writes to pods or secrets outside the node's own namespace. It is an internal authorization-related controller that does not invoke any external webhook endpoints, making it unrelated to webhook-based validation and mutation.
- ✓
ValidatingAdmissionWebhook and MutatingAdmissionWebhook
Why this is correct
ValidatingAdmissionWebhook and MutatingAdmissionWebhook are the admission controllers that serve as the runtime entry points for dynamic admission webhooks. MutatingAdmissionWebhook executes first to transform matching requests, then ValidatingAdmissionWebhook runs to validate them, both calling external HTTPS endpoints defined in MutatingWebhookConfiguration and ValidatingWebhookConfiguration resources. They are the specific controllers responsible for handling custom validation and mutation logic supplied by webhook servers.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Policy Enforcement and Admission Controllers
Key term
OPA Gatekeeper
OPA Gatekeeper is a Kubernetes admission controller that enforces custom security and compliance policies on resources before they are created or updated in a cluster.
Key term
Node Restriction
A Kubernetes admission controller that limits what a kubelet can modify on its own node to prevent privilege escalation and unauthorized access.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.