Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

Which kubectl command creates a validating webhook configuration that calls an external HTTPS endpoint for pod validation?

⚠ Common exam trap

Watch out — candidates often assume there is a dedicated `kubectl create` subcommand for webhooks (like `kubectl create validatingwebhookconfiguration`), but Kubernetes requires webhooks to be defined declaratively via YAML/JSON, not imperatively with flags.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl apply -f webhook.yaml

`kubectl apply -f webhook.yaml` is the standard way to create any Kubernetes resource, including a ValidatingWebhookConfiguration, from a YAML manifest. The manifest defines the webhook's client configuration, including the external HTTPS endpoint, CA bundle, and rules for pod validation. There is no dedicated `kubectl create` subcommand for webhooks; the resource must be defined declaratively in a YAML file.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl create admission webhook --validate

    Why it's wrong here

    The `kubectl create` command only supports a fixed set of built-in resource generators (e.g., deployment, service, configmap), and there is no generator for admission webhook configurations. The `admission` subcommand and `--validate` flag are not recognized, so Kubernetes returns an error. ValidatingWebhookConfiguration is an API object that must be supplied as a manifest file, not constructed via CLI flags.

  • ✗

    kubectl run webhook --image=...

    Why it's wrong here

    `kubectl run` is designed to create a Pod or Deployment from a container image, not to register cluster admission hooks. Even if the image runs a webhook server, the command never creates a ValidatingWebhookConfiguration resource; it only schedules the workload. Without a separate configuration object, the API server cannot know which operations to intercept or how to reach the webhook. Thus, this command is irrelevant to creating a webhook configuration.

  • ✓

    kubectl apply -f webhook.yaml

    Why this is correct

    `kubectl apply -f webhook.yaml` is the correct approach because ValidatingWebhookConfiguration is a declarative API resource defined in YAML. The manifest contains the essential fields: clientConfig (url or service reference and caBundle), rules, failurePolicy, and admissionReviewVersions. Running kubectl apply sends this manifest to the API server, which persists the configuration and immediately activates the webhook for matching requests. This is the only reliable way to create such cluster-scoped admission configurations.

  • ✗

    kubectl create validatingwebhookconfiguration --url=https://...

    Why it's wrong here

    `kubectl create` has no subcommand for `validatingwebhookconfiguration`; the resource type is not among the generators that accept `--url` or similar flags. A ValidatingWebhookConfiguration requires a structured clientConfig with either a URL or service reference, a CA bundle, and rule logic that cannot be expressed conveniently as single CLI parameters. The command line will reject the unknown subcommand or flag. To create the configuration, you must write a YAML file and use `kubectl apply -f`.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.