Courseiva
easyMultiple Choice

CKS Practice Question: Which kubectl command can be used to determine if…

Which kubectl command can be used to determine if anonymous authentication is enabled on the API server?

⚠ Common exam trap

The trap here is that candidates might think `kubectl cluster-info dump` or `kubectl get --raw` can reveal server flags, but these commands do not expose the API server's startup arguments; only inspecting the pod manifest or directly reading the static pod YAML file shows the actual `--anonymous-auth` setting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl get pods -n kube-system kube-apiserver-<node> -o yaml | grep anonymous-auth

The kube-apiserver manifest file (typically located in /etc/kubernetes/manifests/kube-apiserver.yaml) contains the `--anonymous-auth` flag. By inspecting the pod definition via `kubectl get pods -n kube-system kube-apiserver-<node> -o yaml`, you can see the exact command-line arguments passed to the API server, including whether `--anonymous-auth=false` is set (disabled) or absent (enabled by default). This is the most direct and reliable method to check anonymous authentication status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl get --raw /api/v1

    Why it's wrong here

    kubectl get --raw /api/v1 issues a raw HTTP GET to the API server's core API group endpoint, returning discovery information such as supported API resources and versions. This response is generated from the server's runtime API registration, not from the process's startup configuration. It contains no data about command-line flags like --anonymous-auth, which is a kube-apiserver boolean setting controlling whether unauthenticated requests are accepted. Thus, this command cannot reveal whether anonymous access is enabled or disabled.

  • ✗

    kubectl describe node | grep anonymous

    Why it's wrong here

    The kubectl describe node command reports on worker and master nodes' status, including addresses, resource capacity, conditions, and running pods, but it has no field for authentication or authorization settings. The kubelet itself may have an --anonymous-auth flag for its own secure port, but that is separate from the API server's flag and is not surfaced in node descriptions. Additionally, grepping 'anonymous' across node output would not match anything meaningful, because the describe output does not include control-plane component configuration. Therefore this command is irrelevant for checking the API server's anonymous authentication setting.

  • ✗

    kubectl cluster-info dump | grep -i anonymous

    Why it's wrong here

    kubectl cluster-info dump retrieves a comprehensive dump of cluster state, including many resource definitions and logs from all namespaces, which can be extremely verbose and unwieldy. While the dump may include the kube-apiserver's command-line arguments in its logs or event data, the presence of 'anonymous' in that output could come from many unrelated sources, such as RBAC roles, log entries, or other configuration, requiring extensive filtering. It is a heuristic, not a deterministic inspection of the API server's effective flags. The direct and reliable method is to look at the API server pod's manifest, as specified in the correct answer.

  • ✓

    kubectl get pods -n kube-system kube-apiserver-<node> -o yaml | grep anonymous-auth

    Why this is correct

    The correct approach is to retrieve the kube-apiserver static Pod manifest, since the API server runs as a static Pod on the control-plane node and its YAML includes the complete container command and args. Running kubectl get pods -n kube-system kube-apiserver-<node> -o yaml and grepping for 'anonymous-auth' will show whether the flag is explicitly set (true or false) or absent, in which case the default of true applies. This gives a definitive, authoritative answer about the API server's configuration. This command is straightforward, targeted, and leverages kubectl's native access to pod definitions.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.