Courseiva
mediumMultiple Choice

CKS Practice Question: Which kubelet flag prevents the kubelet from…

Which kubelet flag prevents the kubelet from serving anonymous requests?

⚠ Common exam trap

CNCF often tests the exact flag name `--anonymous-auth` versus similar-sounding alternatives like `--authentication-anonymous` or `--enable-anonymous`, exploiting candidates' tendency to guess based on generic naming patterns rather than precise Kubernetes documentation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

--anonymous-auth=false

The kubelet flag `--anonymous-auth=false` disables anonymous authentication, preventing unauthenticated requests from being served. By default, anonymous requests are enabled (`--anonymous-auth=true`), which allows any user without credentials to access the kubelet API. Setting this flag to `false` enforces authentication for all requests, a critical hardening step for cluster security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    --authentication-anonymous=false

    Why it's wrong here

    --authentication-anonymous=false is not a valid kubelet flag. Kubelet authentication settings are configured either with the --anonymous-auth flag or in the kubelet configuration file under authentication.anonymous.enabled. The name resembles an API server flag style, but the kubelet does not accept this exact flag, so it would cause the kubelet to fail to start, not disable anonymous access.

  • ✓

    --anonymous-auth=false

    Why this is correct

    --anonymous-auth=false is the correct kubelet flag. It disables anonymous authentication to the kubelet's HTTPS endpoints on port 10250. When set to false, requests that do not have valid client certificates, bearer tokens, or other accepted credentials are rejected before any authorization checks occur, preventing unauthenticated access to kubelet APIs such as /pods, /exec, and /logs.

  • ✗

    --enable-anonymous=false

    Why it's wrong here

    --enable-anonymous=false is not a valid kubelet flag. Although some kubelet flags use the --enable- prefix (for example, --enable-debugging-handlers and --enable-server), anonymous authentication is not controlled by a flag with this naming convention. The kubelet would reject this unknown flag at startup, making it useless for securing the kubelet.

  • ✗

    --anonymous-requests=false

    Why it's wrong here

    --anonymous-requests=false is not a real kubelet flag. The kubelet's anonymous authentication option is specifically spelled --anonymous-auth, not --anonymous-requests. The term 'anonymous requests' may appear in documentation, but the actual flag name must match exactly; using an invalid name would cause a startup error and leave the kubelet's default anonymous authentication behavior unchanged.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.