easyMultiple Choice
CKS Practice Question: Which flag disables anonymous authentication on…
Which flag disables anonymous authentication on the Kubernetes API server?
⚠ Common exam trap
CNCF often tests the exact flag syntax, and the trap here is that candidates may misremember the flag as `--disable-anonymous-auth` or `--no-anonymous-auth` instead of the correct `--anonymous-auth=false` boolean pattern.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--anonymous-auth=false
The `--anonymous-auth=false` flag explicitly disables anonymous authentication on the Kubernetes API server. By default, anonymous requests are allowed (equivalent to `--anonymous-auth=true`), so setting this flag to `false` prevents unauthenticated users from accessing the API server, which is a key hardening requirement for the CKS exam.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
--disable-anonymous-auth
Why it's wrong here
This flag does not exist. The kube-apiserver only accepts the boolean flag --anonymous-auth. Specifying --disable-anonymous-auth would cause the apiserver to fail with an 'unknown flag' error during startup because the configuration parsing does not recognize it. Even if a similar name were invented, the intended behavior is achieved by the explicit boolean flag with a false value, not by a verb-based flag.
- ✓
--anonymous-auth=false
Why this is correct
This is the correct way to turn off anonymous requests. Setting --anonymous-auth=false tells the apiserver to reject all requests that lack client credentials, returning HTTP 401 Unauthorized. This closes the 'system:anonymous' access path and is a fundamental hardening step for production clusters. Note that this flag alone does not protect service account tokens; it only disables unauthenticated access.
- ✗
--anonymous-auth=true
Why it's wrong here
This flag is actually the default for the kube-apiserver when no value is provided (--anonymous-auth=true). It permits requests without credentials, mapping them to the 'system:anonymous' user and 'system:unauthenticated' group, which can then be restricted via RBAC. Leaving it enabled can expose API endpoints to network users if RBAC is not tightened, so it should be deliberately set to false in security-sensitive environments.
- ✗
--no-anonymous-auth
Why it's wrong here
Like --disable-anonymous-auth, this is not a real flag. The kube-apiserver does not accept negative boolean flags of the form --no-*; it uses a key=value pattern. Attempting to start the apiserver with --no-anonymous-auth will result in an unrecognized flag error and the process will exit. The proper approach is to explicitly pass --anonymous-auth=false.
Go deeper
Related to this question
Learn chapter
Kubernetes Security Fundamentals
Key term
Container Runtime Sandbox
A container runtime sandbox is a security boundary that isolates a container from the host system and other containers, preventing malicious or broken processes from escaping and causing harm.
Key term
etcd Encryption
etcd encryption is the process of protecting data stored in etcd, the key-value store used by Kubernetes, by encoding it so that unauthorized users cannot read it even if they gain access to the storage.
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.