easyMultiple Choice
CKS Practice Question: Which kubectl command can be used to determine if…
Which kubectl command can be used to determine if anonymous authentication is enabled on the API server?
⚠ Common exam trap
The trap here is that candidates might think `kubectl cluster-info dump` or `kubectl get --raw` can reveal server flags, but these commands do not expose the API server's startup arguments; only inspecting the pod manifest or directly reading the static pod YAML file shows the actual `--anonymous-auth` setting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl get pods -n kube-system kube-apiserver-<node> -o yaml | grep anonymous-auth
The kube-apiserver manifest file (typically located in /etc/kubernetes/manifests/kube-apiserver.yaml) contains the `--anonymous-auth` flag. By inspecting the pod definition via `kubectl get pods -n kube-system kube-apiserver-<node> -o yaml`, you can see the exact command-line arguments passed to the API server, including whether `--anonymous-auth=false` is set (disabled) or absent (enabled by default). This is the most direct and reliable method to check anonymous authentication status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl get --raw /api/v1
Why it's wrong here
kubectl get --raw /api/v1 issues a raw HTTP GET to the API server's core API group endpoint, returning discovery information such as supported API resources and versions. This response is generated from the server's runtime API registration, not from the process's startup configuration. It contains no data about command-line flags like --anonymous-auth, which is a kube-apiserver boolean setting controlling whether unauthenticated requests are accepted. Thus, this command cannot reveal whether anonymous access is enabled or disabled.
- ✗
kubectl describe node | grep anonymous
Why it's wrong here
The kubectl describe node command reports on worker and master nodes' status, including addresses, resource capacity, conditions, and running pods, but it has no field for authentication or authorization settings. The kubelet itself may have an --anonymous-auth flag for its own secure port, but that is separate from the API server's flag and is not surfaced in node descriptions. Additionally, grepping 'anonymous' across node output would not match anything meaningful, because the describe output does not include control-plane component configuration. Therefore this command is irrelevant for checking the API server's anonymous authentication setting.
- ✗
kubectl cluster-info dump | grep -i anonymous
Why it's wrong here
kubectl cluster-info dump retrieves a comprehensive dump of cluster state, including many resource definitions and logs from all namespaces, which can be extremely verbose and unwieldy. While the dump may include the kube-apiserver's command-line arguments in its logs or event data, the presence of 'anonymous' in that output could come from many unrelated sources, such as RBAC roles, log entries, or other configuration, requiring extensive filtering. It is a heuristic, not a deterministic inspection of the API server's effective flags. The direct and reliable method is to look at the API server pod's manifest, as specified in the correct answer.
- ✓
kubectl get pods -n kube-system kube-apiserver-<node> -o yaml | grep anonymous-auth
Why this is correct
The correct approach is to retrieve the kube-apiserver static Pod manifest, since the API server runs as a static Pod on the control-plane node and its YAML includes the complete container command and args. Running kubectl get pods -n kube-system kube-apiserver-<node> -o yaml and grepping for 'anonymous-auth' will show whether the flag is explicitly set (true or false) or absent, in which case the default of true applies. This gives a definitive, authoritative answer about the API server's configuration. This command is straightforward, targeted, and leverages kubectl's native access to pod definitions.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.