Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

Which of the following commands creates a ValidatingWebhookConfiguration that uses an OPA Gatekeeper webhook?

⚠ Common exam trap

This exam often tests the distinction between creating the Kubernetes resource that registers the webhook (ValidatingWebhookConfiguration) versus deploying the webhook server itself (Pod/Deployment), and candidates mistakenly think running the Gatekeeper container alone is sufficient to enable admission control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubectl apply -f validatingwebhook.yaml where the webhook's service reference points to the gatekeeper-validating-webhook service.

A ValidatingWebhookConfiguration in Kubernetes must reference a service that handles the admission review request. OPA Gatekeeper exposes its webhook via the `gatekeeper-validating-webhook` service, which listens for `AdmissionReview` requests on the `/v1/admit` endpoint. Applying a YAML manifest that correctly specifies this service reference in the `clientConfig.service` field creates the necessary webhook configuration to integrate Gatekeeper.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kubectl apply -f validatingwebhook.yaml where the webhook's service reference points to the gatekeeper-validating-webhook service.

    Why this is correct

    This is correct because Gatekeeper's admission webhook is implemented as a Kubernetes ValidatingWebhookConfiguration, which is a cluster-scoped API object created declaratively with kubectl apply. The configuration references the gatekeeper-validating-webhook service by name and namespace, telling the API server to forward matching admission requests to that service's HTTPS endpoint. Applying the YAML file registers the webhook with the API server, enabling policy enforcement during pod creation and updates.

  • ✗

    kubectl apply -f constraint.yaml with a ConstraintTemplate.

    Why it's wrong here

    Creating a ConstraintTemplate and a corresponding Constraint via kubectl apply defines Gatekeeper's policy rules and enforcement instances, but these are custom resources consumed by the Gatekeeper controller, not the webhook itself. The ValidatingWebhookConfiguration is what actually tells the Kubernetes API server to call Gatekeeper's webhook service. Without that webhook configuration, no admission requests are sent to Gatekeeper, so this command alone does not create a validating webhook.

  • ✗

    kubectl create validatingwebhook gatekeeper --from-file=webhook.yaml

    Why it's wrong here

    This command is invalid because kubectl has no subcommand named `create validatingwebhook`; the Kubernetes API does not expose a dedicated validatingwebhook resource type for imperative creation. Webhooks are configured by applying a YAML manifest containing a ValidatingWebhookConfiguration object, usually with `kubectl apply -f`. The `--from-file` flag is not a standard option for any kubectl create subcommand, so this would fail with an error.

  • ✗

    kubectl run gatekeeper-webhook --image=openpolicyagent/gatekeeper:v3.14.0

    Why it's wrong here

    Running the openpolicyagent/gatekeeper container as a standalone pod starts the Gatekeeper controller and webhook server, but it does not register the ValidatingWebhookConfiguration with the Kubernetes API server. A Pod alone cannot receive admission requests unless an external configuration points the API server to its service. Gatekeeper is typically deployed as a Deployment with a Service, and the webhook is registered by applying a separate ValidatingWebhookConfiguration manifest.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which kubectl command would you use to create a ValidatingWebhookConfiguration from a YAML file?

easy
  • A.kubectl run webhook --image=webhook --restart=Never
  • ✓ B.kubectl apply -f webhook.yaml
  • C.kubectl create -f webhook.yaml
  • D.kubectl expose deployment webhook --port=443

Why B: `kubectl apply -f webhook.yaml` is the standard command to create or update Kubernetes resources from a YAML file, including a ValidatingWebhookConfiguration. This command uses declarative management, applying the configuration defined in the file to the cluster, which is the recommended approach for creating admission webhooks.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.