Courseiva
mediumMultiple Choice

CKS Practice Question: Which admission plugin should be enabled to…

Which admission plugin should be enabled to prevent kubelets from modifying Node objects they should not have access to?

⚠ Common exam trap

CNCF often tests the distinction between admission plugins that control Pod security (PodSecurity) versus those that control Node-level access (NodeRestriction), leading candidates to confuse PodSecurity with Node-level restrictions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NodeRestriction

The NodeRestriction admission plugin limits the kubelet's ability to modify Node and Pod objects to only those it is authorized to manage based on its credentials. It ensures a kubelet can only label, taint, or update status on its own Node object and cannot modify other Nodes, preventing privilege escalation or misconfiguration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    NamespaceLifecycle

    Why it's wrong here

    NamespaceLifecycle is an admission plugin that manages the lifecycle of namespaces, preventing the deletion of system-critical namespaces like kube-system and kube-public, and rejecting object creation in namespaces that are in the Terminating phase. However, it has no mechanism to restrict what a kubelet can modify on its own node object or other cluster resources. Kubelet authorization is outside the scope of namespace lifecycle management, so this plugin cannot address the specific threat of a malicious or compromised kubelet modifying node metadata.

  • ✓

    NodeRestriction

    Why this is correct

    NodeRestriction is the admission plugin specifically designed to constrain kubelet permissions. It enforces that a kubelet identified by its credentials (e.g., user system:kubelet:<nodeName>) can only update its own node object, and even then, it can only modify allowed fields such as status, pods, and specific annotations, while blocking changes to labels, taints, or other critical scheduling fields. This plugin directly prevents a kubelet from tampering with node objects to influence scheduling or evade security controls. Enabling NodeRestriction is a mandatory hardening step and works alongside RBAC to provide defense-in-depth for kubelet access.

  • ✗

    PodSecurity

    Why it's wrong here

    PodSecurity is an admission plugin that enforces the Pod Security Standards (privileged, baseline, restricted) by validating pod specifications at creation or update time. It controls container-level security contexts, such as privileged containers, host namespaces, and allowed capabilities. Kubelets, however, are not pods and do not go through pod admission; their actions are authenticated and authorized separately, typically via x509 certificates or bootstrap tokens. Therefore, PodSecurity cannot impose any restriction on what a kubelet can modify on node objects, making it irrelevant to the kubelet-specific security concern.

  • ✗

    ServiceAccount

    Why it's wrong here

    ServiceAccount is an admission plugin that governs how service accounts are associated with pods and whether their tokens are automatically mounted. It validates that pods reference valid service accounts and can mutate the pod spec to include token volumes when automounting is enabled. This plugin does not affect kubelets, which use their own node-level credentials (e.g., node certificates or kubeconfigs) rather than service accounts. Since kubelet actions bypass this admission hook, enabling ServiceAccount provides no control over kubelet modifications to node objects or other cluster resources.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.