easyMultiple Choice
CKS Practice Question: Which flag on the kubelet disables anonymous…
Which flag on the kubelet disables anonymous access?
⚠ Common exam trap
CNCF often tests the exact flag name and syntax, so candidates may confuse `--anonymous-auth` with `--enable-anonymous-auth` or invent non-existent flags like `--disable-anonymous` or `--no-anonymous`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--anonymous-auth=false
The `--anonymous-auth` flag on the kubelet controls whether anonymous requests are allowed. Setting `--anonymous-auth=false` explicitly disables anonymous access, requiring all requests to present valid authentication credentials. This is a critical hardening measure to prevent unauthenticated users from interacting with the kubelet API.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
--anonymous-auth=false
Why this is correct
The kubelet controls anonymous access through the --anonymous-auth flag, which is a boolean parameter that defaults to true. Setting this flag to false is the exact, documented mechanism to require authentication for every request to the kubelet's HTTPS endpoint, including requests from the kube-apiserver. This matches the equivalent flag used on the Kubernetes API server, making it the correct and precise way to disable unauthenticated access.
- ✗
--disable-anonymous
Why it's wrong here
The kubelet does not have a --disable-anonymous flag in its configuration schema. Kubernetes flags are typically named after the setting they modify, and the actual flag is --anonymous-auth, which must be set to the explicit boolean value false. Since --disable-anonymous is not a recognized kubelet flag, issuing it would cause the kubelet to exit with an 'unknown flag' error, leaving anonymous access in its default enabled state.
- ✗
--no-anonymous
Why it's wrong here
There is no --no-anonymous boolean flag accepted by the kubelet. While a 'no-' prefix might intuitively appear to negate a feature, Kubernetes flags are not generally constructed that way; instead, they take an explicit value. To disable anonymous authentication, the correct syntax is --anonymous-auth=false, which clarifies the setting's state. Using a fabricated flag like --no-anonymous would be ignored or rejected, and would not alter the kubelet's authentication policy.
- ✗
--enable-anonymous-auth=false
Why it's wrong here
Although --enable-anonymous-auth=false might seem like a logical negation of an 'enable' flag, the kubelet's real configuration parameter is simply --anonymous-auth. The 'enable' prefix is not used for this particular setting, and the kubelet does not recognize --enable-anonymous-auth. Passing this incorrect flag would result in a command-line parse error, meaning the kubelet would not start or would continue using the default anonymous-auth=true, leaving anonymous access enabled.
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.