Courseiva
easyMultiple Choice

CKS Practice Question: Is a recommended CIS benchmark setting for the…

Which of the following is a recommended CIS benchmark setting for the kubelet?

⚠ Common exam trap

CNCF often tests the distinction between kubelet flags that control authentication versus authorization, and candidates may confuse `--anonymous-auth` with `--authentication-token-webhook` or incorrectly assume that disabling anonymous auth also blocks legitimate service account tokens.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

--anonymous-auth=false

The CIS benchmark for Kubernetes recommends disabling anonymous authentication on the kubelet to ensure that all requests to the kubelet API are authenticated. Setting `--anonymous-auth=false` forces the kubelet to reject requests from unauthenticated users, preventing potential unauthorized access to node-level operations such as pod logs, exec, and port-forwarding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    --anonymous-auth=true

    Why it's wrong here

    Setting `--anonymous-auth=true` on the API server or kubelet permits unauthenticated requests to reach the component, meaning the system will accept requests from users and processes that have not provided a valid credential. In CIS Benchmark section 4.2 (and similar kubelet sections), anonymous authentication must be disabled because it can allow an attacker who has network access to perform reconnaissance or trigger actions without needing to compromise a service account or user identity.

  • ✓

    --anonymous-auth=false

    Why this is correct

    Setting `--anonymous-auth=false` explicitly rejects all requests that cannot be authenticated, including those mapped to `system:anonymous` and `system:unauthenticated`. This is the CIS-recommended hardening control because it forces every interaction with the control plane or kubelet to present a valid X.509 client certificate, bearer token, or other approved credential, thereby eliminating a common attack path where an unauthenticated remote actor can query system metadata or issue unprivileged requests.

  • ✗

    --protect-kernel-defaults=false

    Why it's wrong here

    Setting `--protect-kernel-defaults=false` tells the kubelet to ignore checks for kernel parameter settings such as `vm.overcommit_memory` and `net.ipv4.ip_forward`, and it does not enforce that those values follow the recommendations. CIS specifically requires this flag to be `true` so the kubelet refuses to start if the underlying host kernel tunables are not hardened, preventing containers from running on a host that is vulnerable to memory overcommit, IP forwarding abuse, or other kernel-level attacks.

  • ✗

    --read-only-port=10255

    Why it's wrong here

    Setting `--read-only-port=10255` enables the kubelet's legacy unauthenticated read-only port, allowing anyone who can reach that port to enumerate node state, running containers, and pod specifications without any authentication. The CIS Benchmark mandates `--read-only-port=0` to disable this port entirely, because any data exposed over this channel can aid lateral movement or reveal sensitive metadata that should only be accessible with kubelet credentials.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.