Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

Which kubectl command would you use to create a ValidatingWebhookConfiguration from a YAML file?

⚠ Common exam trap

In the CKS exam, candidates often confuse `kubectl create` and `kubectl apply`. While `kubectl create -f` creates a resource, `kubectl apply -f` is the preferred declarative approach for managing resources like ValidatingWebhookConfiguration because it supports idempotent updates and better handles changes over time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl apply -f webhook.yaml

`kubectl apply -f webhook.yaml` is the standard command to create or update Kubernetes resources from a YAML file, including a ValidatingWebhookConfiguration. This command uses declarative management, applying the configuration defined in the file to the cluster, which is the recommended approach for creating admission webhooks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubectl run webhook --image=webhook --restart=Never

    Why it's wrong here

    This command creates a standalone Pod using the --restart=Never flag, which forces a Pod rather than a Deployment. It does not create a ValidatingWebhookConfiguration, and the arbitrary image 'webhook' is irrelevant to the API server's admission configuration. To register an admission webhook, you must provide a YAML manifest with the proper kind and apiVersion, then apply it.

  • ✓

    kubectl apply -f webhook.yaml

    Why this is correct

    kubectl apply is the standard declarative approach: it sends the entire ValidatingWebhookConfiguration manifest to the API server, which then stores the resource and records the last-applied-configuration so future applies produce a precise three-way merge patch. This idempotent behavior lets you use the same command to both create and update the webhook, which is why it is the recommended method for managing admission webhook resources.

  • ✗

    kubectl create -f webhook.yaml

    Why it's wrong here

    This works only on the first run, because kubectl create is imperative: it attempts to create a brand-new resource and returns an error if a ValidatingWebhookConfiguration with that name already exists. Unlike apply, create does not compute a diff against the live object or the last-applied configuration, so it is unsuitable for updating webhook definitions. Prefer apply for declarative management to avoid breaking re-runs.

  • ✗

    kubectl expose deployment webhook --port=443

    Why it's wrong here

    This command creates a Service object that fronts the pods of a Deployment named 'webhook' on port 443, but it does not register any admission webhook with the API server. A ValidatingWebhookConfiguration is a separate, cluster-scoped resource that tells the kube-apiserver which URL or service to call during request validation. Using expose here would not produce the required configuration kind, and no service definition alone can enable admission control.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.