mediumMultiple Choice
CKS Practice Question: Which kubelet flag prevents the kubelet from…
Which kubelet flag prevents the kubelet from serving anonymous requests?
⚠ Common exam trap
CNCF often tests the exact flag name `--anonymous-auth` versus similar-sounding alternatives like `--authentication-anonymous` or `--enable-anonymous`, exploiting candidates' tendency to guess based on generic naming patterns rather than precise Kubernetes documentation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--anonymous-auth=false
The kubelet flag `--anonymous-auth=false` disables anonymous authentication, preventing unauthenticated requests from being served. By default, anonymous requests are enabled (`--anonymous-auth=true`), which allows any user without credentials to access the kubelet API. Setting this flag to `false` enforces authentication for all requests, a critical hardening step for cluster security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
--authentication-anonymous=false
Why it's wrong here
--authentication-anonymous=false is not a valid kubelet flag. Kubelet authentication settings are configured either with the --anonymous-auth flag or in the kubelet configuration file under authentication.anonymous.enabled. The name resembles an API server flag style, but the kubelet does not accept this exact flag, so it would cause the kubelet to fail to start, not disable anonymous access.
- ✓
--anonymous-auth=false
Why this is correct
--anonymous-auth=false is the correct kubelet flag. It disables anonymous authentication to the kubelet's HTTPS endpoints on port 10250. When set to false, requests that do not have valid client certificates, bearer tokens, or other accepted credentials are rejected before any authorization checks occur, preventing unauthenticated access to kubelet APIs such as /pods, /exec, and /logs.
- ✗
--enable-anonymous=false
Why it's wrong here
--enable-anonymous=false is not a valid kubelet flag. Although some kubelet flags use the --enable- prefix (for example, --enable-debugging-handlers and --enable-server), anonymous authentication is not controlled by a flag with this naming convention. The kubelet would reject this unknown flag at startup, making it useless for securing the kubelet.
- ✗
--anonymous-requests=false
Why it's wrong here
--anonymous-requests=false is not a real kubelet flag. The kubelet's anonymous authentication option is specifically spelled --anonymous-auth, not --anonymous-requests. The term 'anonymous requests' may appear in documentation, but the actual flag name must match exactly; using an invalid name would cause a startup error and leave the kubelet's default anonymous authentication behavior unchanged.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.