Courseiva
mediumMultiple Choice

CKS Practice Question: Which kubectl command creates a Role named…

Which kubectl command creates a Role named 'pod-reader' that allows only 'get', 'list', and 'watch' on pods in namespace 'ns1'?

⚠ Common exam trap

Many exam-takers confuse `kubectl create role` with `kubectl create clusterrole` (option A) or mistakenly use `--verb=*` (option C) thinking it means 'only these verbs', when in fact it grants all verbs, violating the principle of least privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl create role pod-reader --verb=get,list,watch --resource=pods --namespace=ns1

The `kubectl create role` command creates a Role (namespaced resource) with the specified verbs and resources in the given namespace. The `--verb=get,list,watch` and `--resource=pods` flags define the exact permissions, and `--namespace=ns1` scopes the Role to that namespace, which matches the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl create clusterrole pod-reader --verb=get,list,watch --resource=pods

    Why it's wrong here

    The `kubectl create clusterrole` command creates a ClusterRole, which is a cluster-scoped RBAC resource that applies across all namespaces. Since the question asks for a namespaced Role (implied by the need to limit scope to a specific namespace like ns1), a ClusterRole is incorrect because it grants permissions beyond the intended namespace boundary. The absence of `--namespace=ns1` further confirms this command targets the whole cluster, not a single namespace.

  • ✓

    kubectl create role pod-reader --verb=get,list,watch --resource=pods --namespace=ns1

    Why this is correct

    This is the correct command because `kubectl create role` creates a namespaced Role, and the `--namespace=ns1` flag scopes it to the namespace ns1. The `--verb=get,list,watch` precisely defines the allowed actions, and `--resource=pods` targets the Pods resource. This matches exactly the requirement to create a role named `pod-reader` with read-only access to pods in namespace ns1.

  • ✗

    kubectl create role pod-reader --verb=* --resource=pods --namespace=ns1

    Why it's wrong here

    Using `--verb=*` in a Role grants all possible verbs (create, delete, update, patch, list, watch, etc.) on the specified resource, which is far broader than the required get, list, and watch. The wildcard is an anti-pattern for least privilege because it permits destructive actions and any future verbs Kubernetes may add. The correct specification should enumerate only the three read verbs to satisfy the requirement without over-permissioning.

  • ✗

    kubectl create rolebinding pod-reader --role=pod-reader --serviceaccount=ns1:default

    Why it's wrong here

    This command creates a RoleBinding, not a Role. A RoleBinding is used to bind an existing Role to a subject (like a ServiceAccount), but it does not create the Role itself. Since the question explicitly asks to create a role named pod-reader, this command would fail to create the Role object; instead it would attempt to reference a Role that may not yet exist, likely causing an error or an unintended binding.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.