CKS Minimize Microservice Vulnerabilities Practice Question
Which command creates a validating webhook configuration that checks all pods in the cluster?
⚠ Common exam trap
The CKS exam often tests the distinction between mutating and validating webhooks. Candidates may confuse `kubectl create mutatingwebhookconfiguration` with the validating variant, or assume `kubectl apply` with a flag can create a validating webhook.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl create validatingwebhookconfiguration my-webhook --from-file=webhook.yaml
`kubectl create validatingwebhookconfiguration` is the specific command to create a ValidatingWebhookConfiguration resource from a YAML file, which can be configured to intercept and validate pod creation requests across the cluster. This resource allows you to define a webhook that checks all pods before they are admitted, enforcing custom validation logic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl create mutatingwebhookconfiguration my-webhook --from-file=webhook.yaml
Why it's wrong here
Mutating webhooks may alter objects during admission; validating webhooks only accept or reject them, so this cannot enforce the requested checks. It is tempting because the create command and manifest structure are otherwise identical, and mutatingwebhookconfiguration would be correct if pods needed defaulting or patching.
- ✗
kubectl run webhook --image=webhook
Why it's wrong here
kubectl run only starts a container; it registers no admission configuration, so no webhook ever validates pods. It is tempting because the webhook server itself must run somewhere, and this command would be correct for launching that backing service before wiring the configuration to it.
- ✓
kubectl create validatingwebhookconfiguration my-webhook --from-file=webhook.yaml
Why this is correct
The `kubectl create validatingwebhookconfiguration` subcommand registers a ValidatingWebhookConfiguration object, which the API server consults before admitting any pod. Because the webhook's `rules` field can scope to `pods` across all namespaces, it satisfies the stem's requirement to check every pod cluster-wide, unlike namespace-scoped alternatives.
- ✗
kubectl apply -f webhook.yaml --validating
Why it's wrong here
kubectl apply has no --validating flag; it simply submits the manifest, and the API server rejects the unknown flag. It is tempting because applying a YAML file is the normal way to register a webhook, and the command would be correct if the manifest's kind already specified ValidatingWebhookConfiguration.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.