CKS Minimize Microservice Vulnerabilities Practice Question
Which command can be used to view the current set of admission webhooks in the cluster?
⚠ Common exam trap
Candidates often assume a generic `webhooks` or `admissionwebhooks` resource exists, but Kubernetes requires the exact resource names `validatingwebhookconfigurations` and `mutatingwebhookconfigurations`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl get validatingwebhookconfigurations
Admission webhooks in Kubernetes are configured via `ValidatingWebhookConfiguration` and `MutatingWebhookConfiguration` resources. The command `kubectl get validatingwebhookconfigurations` retrieves all validating admission webhooks currently registered in the cluster, which is the standard way to list them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl get webhooks
Why it's wrong here
This is invalid because 'webhooks' is not a recognized Kubernetes resource type. The 'kubectl get' command only works with registered API resources, and there is no such resource as 'webhooks' in the core API. Admission webhooks are not a standalone resource; they live inside ValidatingWebhookConfiguration and MutatingWebhookConfiguration objects, so this command returns an error instead of a list.
- ✓
kubectl get validatingwebhookconfigurations
Why this is correct
This is the correct command. ValidatingWebhookConfiguration is a real admissionregistration.k8s.io/v1 resource that defines validation webhooks. Running 'kubectl get validatingwebhookconfigurations' lists all registered validating webhook configurations, which contain the webhook client configuration, rules, and failure policy. These resources are cluster-scoped and directly represent the admission webhooks that validate API requests.
- ✗
kubectl get webhookconfigurations
Why it's wrong here
This is not a valid resource type. The Kubernetes API has separate resource types: ValidatingWebhookConfiguration and MutatingWebhookConfiguration; there is no generic 'webhookconfigurations' aggregate. Running this command would result in an error from the API server indicating the resource type is unknown. To see webhook configurations, you must use the specific plural names for each type, not a generic term.
- ✗
kubectl get admissionwebhooks
Why it's wrong here
This is also invalid because 'admissionwebhooks' is not a resource type. Admission webhooks are a concept that spans two distinct API objects: ValidatingWebhookConfiguration and MutatingWebhookConfiguration. There is no single resource that groups them; you must query each type separately. The command would fail with a 'resource type not found' error.
Go deeper
Related to this question
Learn chapter
Kubernetes Security Fundamentals
Key term
Admission Controllers
Admission controllers are plugins that intercept and process requests to the Kubernetes API server after authentication and authorization, but before the request is persisted, allowing policies to be enforced on objects being created, modified, or deleted.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.