Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

Which admission controller is responsible for validating and mutating requests based on webhooks?

⚠ Common exam trap

The exam often tests the distinction between built-in admission controllers (like PodSecurityPolicy or ServiceAccount) and webhook-based controllers, expecting candidates to know that only ValidatingAdmissionWebhook and MutatingAdmissionWebhook rely on external HTTP callbacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ValidatingAdmissionWebhook and MutatingAdmissionWebhook

The ValidatingAdmissionWebhook and MutatingAdmissionWebhook admission controllers are specifically designed to intercept admission requests and call external webhooks to validate or mutate the request. MutatingAdmissionWebhook can modify the object (e.g., inject sidecar containers) before it is persisted, while ValidatingAdmissionWebhook only validates and can reject the request. These controllers are the only ones that delegate admission decisions to external HTTP callbacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ServiceAccount

    Why it's wrong here

    ServiceAccount is a built-in admission controller that automates service account creation and token injection, such as assigning the default service account to pods and projecting service account tokens into filesystems. It is not webhook-based and performs no external HTTP callbacks, so it cannot be responsible for custom validation or mutation via admission webhooks.

  • ✗

    PodSecurityPolicy

    Why it's wrong here

    PodSecurityPolicy (PSP) was a built-in admission controller that enforced pod security constraints like privileged mode and host namespaces, but it was deprecated in 1.21 and removed in 1.25, and it never used webhooks. It operated via static policy evaluation inside the kube-apiserver, not by calling external webhook servers, so it cannot be the required controller for webhook-driven validation and mutation.

  • ✗

    NodeRestriction

    Why it's wrong here

    NodeRestriction is an admission controller that restricts which Node objects a node credential can modify, enforcing API access limits for nodes such as denying writes to pods or secrets outside the node's own namespace. It is an internal authorization-related controller that does not invoke any external webhook endpoints, making it unrelated to webhook-based validation and mutation.

  • ✓

    ValidatingAdmissionWebhook and MutatingAdmissionWebhook

    Why this is correct

    ValidatingAdmissionWebhook and MutatingAdmissionWebhook are the admission controllers that serve as the runtime entry points for dynamic admission webhooks. MutatingAdmissionWebhook executes first to transform matching requests, then ValidatingAdmissionWebhook runs to validate them, both calling external HTTPS endpoints defined in MutatingWebhookConfiguration and ValidatingWebhookConfiguration resources. They are the specific controllers responsible for handling custom validation and mutation logic supplied by webhook servers.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.