mediumMultiple Choice
CKS Practice Question: Which kubectl command creates a Role named…
Which kubectl command creates a Role named 'pod-reader' that allows only 'get', 'list', and 'watch' on pods in namespace 'ns1'?
⚠ Common exam trap
Many exam-takers confuse `kubectl create role` with `kubectl create clusterrole` (option A) or mistakenly use `--verb=*` (option C) thinking it means 'only these verbs', when in fact it grants all verbs, violating the principle of least privilege.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl create role pod-reader --verb=get,list,watch --resource=pods --namespace=ns1
The `kubectl create role` command creates a Role (namespaced resource) with the specified verbs and resources in the given namespace. The `--verb=get,list,watch` and `--resource=pods` flags define the exact permissions, and `--namespace=ns1` scopes the Role to that namespace, which matches the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl create clusterrole pod-reader --verb=get,list,watch --resource=pods
Why it's wrong here
The `kubectl create clusterrole` command creates a ClusterRole, which is a cluster-scoped RBAC resource that applies across all namespaces. Since the question asks for a namespaced Role (implied by the need to limit scope to a specific namespace like ns1), a ClusterRole is incorrect because it grants permissions beyond the intended namespace boundary. The absence of `--namespace=ns1` further confirms this command targets the whole cluster, not a single namespace.
- ✓
kubectl create role pod-reader --verb=get,list,watch --resource=pods --namespace=ns1
Why this is correct
This is the correct command because `kubectl create role` creates a namespaced Role, and the `--namespace=ns1` flag scopes it to the namespace ns1. The `--verb=get,list,watch` precisely defines the allowed actions, and `--resource=pods` targets the Pods resource. This matches exactly the requirement to create a role named `pod-reader` with read-only access to pods in namespace ns1.
- ✗
kubectl create role pod-reader --verb=* --resource=pods --namespace=ns1
Why it's wrong here
Using `--verb=*` in a Role grants all possible verbs (create, delete, update, patch, list, watch, etc.) on the specified resource, which is far broader than the required get, list, and watch. The wildcard is an anti-pattern for least privilege because it permits destructive actions and any future verbs Kubernetes may add. The correct specification should enumerate only the three read verbs to satisfy the requirement without over-permissioning.
- ✗
kubectl create rolebinding pod-reader --role=pod-reader --serviceaccount=ns1:default
Why it's wrong here
This command creates a RoleBinding, not a Role. A RoleBinding is used to bind an existing Role to a subject (like a ServiceAccount), but it does not create the Role itself. Since the question explicitly asks to create a role named pod-reader, this command would fail to create the Role object; instead it would attempt to reference a Role that may not yet exist, likely causing an error or an unintended binding.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.