CKS Minimize Microservice Vulnerabilities Practice Question
Which kubectl command would you use to create a ValidatingWebhookConfiguration from a YAML file?
⚠ Common exam trap
In the CKS exam, candidates often confuse `kubectl create` and `kubectl apply`. While `kubectl create -f` creates a resource, `kubectl apply -f` is the preferred declarative approach for managing resources like ValidatingWebhookConfiguration because it supports idempotent updates and better handles changes over time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl apply -f webhook.yaml
`kubectl apply -f webhook.yaml` is the standard command to create or update Kubernetes resources from a YAML file, including a ValidatingWebhookConfiguration. This command uses declarative management, applying the configuration defined in the file to the cluster, which is the recommended approach for creating admission webhooks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl run webhook --image=webhook --restart=Never
Why it's wrong here
This command creates a standalone Pod using the --restart=Never flag, which forces a Pod rather than a Deployment. It does not create a ValidatingWebhookConfiguration, and the arbitrary image 'webhook' is irrelevant to the API server's admission configuration. To register an admission webhook, you must provide a YAML manifest with the proper kind and apiVersion, then apply it.
- ✓
kubectl apply -f webhook.yaml
Why this is correct
kubectl apply is the standard declarative approach: it sends the entire ValidatingWebhookConfiguration manifest to the API server, which then stores the resource and records the last-applied-configuration so future applies produce a precise three-way merge patch. This idempotent behavior lets you use the same command to both create and update the webhook, which is why it is the recommended method for managing admission webhook resources.
- ✗
kubectl create -f webhook.yaml
Why it's wrong here
This works only on the first run, because kubectl create is imperative: it attempts to create a brand-new resource and returns an error if a ValidatingWebhookConfiguration with that name already exists. Unlike apply, create does not compute a diff against the live object or the last-applied configuration, so it is unsuitable for updating webhook definitions. Prefer apply for declarative management to avoid breaking re-runs.
- ✗
kubectl expose deployment webhook --port=443
Why it's wrong here
This command creates a Service object that fronts the pods of a Deployment named 'webhook' on port 443, but it does not register any admission webhook with the API server. A ValidatingWebhookConfiguration is a separate, cluster-scoped resource that tells the kube-apiserver which URL or service to call during request validation. Using expose here would not produce the required configuration kind, and no service definition alone can enable admission control.
Go deeper
Related to this question
Learn chapter
Cluster Hardening: Node and Container Security
Key term
Admission Controllers
Admission controllers are plugins that intercept and process requests to the Kubernetes API server after authentication and authorization, but before the request is persisted, allowing policies to be enforced on objects being created, modified, or deleted.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.