easyMultiple Choice
CKS Practice Question: Which admission plugin is recommended by the CIS…
Which admission plugin is recommended by the CIS Kubernetes Benchmark to restrict the kubelet's ability to modify nodes?
⚠ Common exam trap
Test-takers frequently confuse admission plugins that control pod security (like SecurityContextDeny or PodNodeSelector) with the specific plugin that restricts kubelet node modification, leading them to pick a security-focused option that does not address the kubelet's API access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NodeRestriction
The NodeRestriction admission plugin is recommended by the CIS Kubernetes Benchmark to restrict the kubelet's ability to modify nodes. It limits the kubelet's permissions to only modify its own node and its own pods, preventing it from altering other nodes or performing unauthorized operations. This plugin enforces a security boundary by rejecting requests that attempt to modify node labels, taints, or status outside the kubelet's assigned scope.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
NodeRestriction
Why this is correct
NodeRestriction limits the kubelet's own credentials so it can only modify its own Node object and the Pods bound to it, satisfying the CIS Benchmark recommendation to restrict kubelet node modification. Without it, a compromised node could alter labels or taints cluster-wide.
- ✗
PodNodeSelector
Why it's wrong here
PodNodeSelector constrains which nodes a pod may be scheduled onto via namespace labels; it does not restrict the kubelet's node modification rights. It is tempting because it is a genuine admission plugin, and it would be correct when the requirement is enforcing node placement constraints per namespace.
- ✗
SecurityContextDeny
Why it's wrong here
SecurityContextDeny blocks pods using privileged security context fields, but it does not govern kubelet authorisation to modify node objects. It is tempting because it is a security-focused admission plugin, and it would be correct where the requirement is preventing pods from setting privileged or host-level security contexts.
- ✗
AlwaysPullImages
Why it's wrong here
AlwaysPullImages forces image pulls on every pod creation to prevent stale cached images; it does not restrict kubelet node modification. It is tempting because it is a genuine CIS-recommended admission plugin, and it would be correct when the requirement is ensuring images are always fetched from the registry.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.