Courseiva
easyMultiple Choice

CKS Practice Question: Which flag on the kubelet disables anonymous…

Which flag on the kubelet disables anonymous access?

⚠ Common exam trap

CNCF often tests the exact flag name and syntax, so candidates may confuse `--anonymous-auth` with `--enable-anonymous-auth` or invent non-existent flags like `--disable-anonymous` or `--no-anonymous`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

--anonymous-auth=false

The `--anonymous-auth` flag on the kubelet controls whether anonymous requests are allowed. Setting `--anonymous-auth=false` explicitly disables anonymous access, requiring all requests to present valid authentication credentials. This is a critical hardening measure to prevent unauthenticated users from interacting with the kubelet API.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    --anonymous-auth=false

    Why this is correct

    The kubelet controls anonymous access through the --anonymous-auth flag, which is a boolean parameter that defaults to true. Setting this flag to false is the exact, documented mechanism to require authentication for every request to the kubelet's HTTPS endpoint, including requests from the kube-apiserver. This matches the equivalent flag used on the Kubernetes API server, making it the correct and precise way to disable unauthenticated access.

  • ✗

    --disable-anonymous

    Why it's wrong here

    The kubelet does not have a --disable-anonymous flag in its configuration schema. Kubernetes flags are typically named after the setting they modify, and the actual flag is --anonymous-auth, which must be set to the explicit boolean value false. Since --disable-anonymous is not a recognized kubelet flag, issuing it would cause the kubelet to exit with an 'unknown flag' error, leaving anonymous access in its default enabled state.

  • ✗

    --no-anonymous

    Why it's wrong here

    There is no --no-anonymous boolean flag accepted by the kubelet. While a 'no-' prefix might intuitively appear to negate a feature, Kubernetes flags are not generally constructed that way; instead, they take an explicit value. To disable anonymous authentication, the correct syntax is --anonymous-auth=false, which clarifies the setting's state. Using a fabricated flag like --no-anonymous would be ignored or rejected, and would not alter the kubelet's authentication policy.

  • ✗

    --enable-anonymous-auth=false

    Why it's wrong here

    Although --enable-anonymous-auth=false might seem like a logical negation of an 'enable' flag, the kubelet's real configuration parameter is simply --anonymous-auth. The 'enable' prefix is not used for this particular setting, and the kubelet does not recognize --enable-anonymous-auth. Passing this incorrect flag would result in a command-line parse error, meaning the kubelet would not start or would continue using the default anonymous-auth=true, leaving anonymous access enabled.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.