CKS Minimize Microservice Vulnerabilities Practice Question
Which of the following commands creates a ValidatingWebhookConfiguration that uses an OPA Gatekeeper webhook?
⚠ Common exam trap
This exam often tests the distinction between creating the Kubernetes resource that registers the webhook (ValidatingWebhookConfiguration) versus deploying the webhook server itself (Pod/Deployment), and candidates mistakenly think running the Gatekeeper container alone is sufficient to enable admission control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kubectl apply -f validatingwebhook.yaml where the webhook's service reference points to the gatekeeper-validating-webhook service.
A ValidatingWebhookConfiguration in Kubernetes must reference a service that handles the admission review request. OPA Gatekeeper exposes its webhook via the `gatekeeper-validating-webhook` service, which listens for `AdmissionReview` requests on the `/v1/admit` endpoint. Applying a YAML manifest that correctly specifies this service reference in the `clientConfig.service` field creates the necessary webhook configuration to integrate Gatekeeper.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
kubectl apply -f validatingwebhook.yaml where the webhook's service reference points to the gatekeeper-validating-webhook service.
Why this is correct
This is correct because Gatekeeper's admission webhook is implemented as a Kubernetes ValidatingWebhookConfiguration, which is a cluster-scoped API object created declaratively with kubectl apply. The configuration references the gatekeeper-validating-webhook service by name and namespace, telling the API server to forward matching admission requests to that service's HTTPS endpoint. Applying the YAML file registers the webhook with the API server, enabling policy enforcement during pod creation and updates.
- ✗
kubectl apply -f constraint.yaml with a ConstraintTemplate.
Why it's wrong here
Creating a ConstraintTemplate and a corresponding Constraint via kubectl apply defines Gatekeeper's policy rules and enforcement instances, but these are custom resources consumed by the Gatekeeper controller, not the webhook itself. The ValidatingWebhookConfiguration is what actually tells the Kubernetes API server to call Gatekeeper's webhook service. Without that webhook configuration, no admission requests are sent to Gatekeeper, so this command alone does not create a validating webhook.
- ✗
kubectl create validatingwebhook gatekeeper --from-file=webhook.yaml
Why it's wrong here
This command is invalid because kubectl has no subcommand named `create validatingwebhook`; the Kubernetes API does not expose a dedicated validatingwebhook resource type for imperative creation. Webhooks are configured by applying a YAML manifest containing a ValidatingWebhookConfiguration object, usually with `kubectl apply -f`. The `--from-file` flag is not a standard option for any kubectl create subcommand, so this would fail with an error.
- ✗
kubectl run gatekeeper-webhook --image=openpolicyagent/gatekeeper:v3.14.0
Why it's wrong here
Running the openpolicyagent/gatekeeper container as a standalone pod starts the Gatekeeper controller and webhook server, but it does not register the ValidatingWebhookConfiguration with the Kubernetes API server. A Pod alone cannot receive admission requests unless an external configuration points the API server to its service. Gatekeeper is typically deployed as a Deployment with a Service, and the webhook is registered by applying a separate ValidatingWebhookConfiguration manifest.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which kubectl command would you use to create a ValidatingWebhookConfiguration from a YAML file?
easy- A.kubectl run webhook --image=webhook --restart=Never
- ✓ B.kubectl apply -f webhook.yaml
- C.kubectl create -f webhook.yaml
- D.kubectl expose deployment webhook --port=443
Why B: `kubectl apply -f webhook.yaml` is the standard command to create or update Kubernetes resources from a YAML file, including a ValidatingWebhookConfiguration. This command uses declarative management, applying the configuration defined in the file to the cluster, which is the recommended approach for creating admission webhooks.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.