easyMultiple Choice
CKS Practice Question: Is a recommended CIS benchmark setting for the…
Which of the following is a recommended CIS benchmark setting for the kubelet?
⚠ Common exam trap
CNCF often tests the distinction between kubelet flags that control authentication versus authorization, and candidates may confuse `--anonymous-auth` with `--authentication-token-webhook` or incorrectly assume that disabling anonymous auth also blocks legitimate service account tokens.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--anonymous-auth=false
The CIS benchmark for Kubernetes recommends disabling anonymous authentication on the kubelet to ensure that all requests to the kubelet API are authenticated. Setting `--anonymous-auth=false` forces the kubelet to reject requests from unauthenticated users, preventing potential unauthorized access to node-level operations such as pod logs, exec, and port-forwarding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
--anonymous-auth=true
Why it's wrong here
Setting `--anonymous-auth=true` on the API server or kubelet permits unauthenticated requests to reach the component, meaning the system will accept requests from users and processes that have not provided a valid credential. In CIS Benchmark section 4.2 (and similar kubelet sections), anonymous authentication must be disabled because it can allow an attacker who has network access to perform reconnaissance or trigger actions without needing to compromise a service account or user identity.
- ✓
--anonymous-auth=false
Why this is correct
Setting `--anonymous-auth=false` explicitly rejects all requests that cannot be authenticated, including those mapped to `system:anonymous` and `system:unauthenticated`. This is the CIS-recommended hardening control because it forces every interaction with the control plane or kubelet to present a valid X.509 client certificate, bearer token, or other approved credential, thereby eliminating a common attack path where an unauthenticated remote actor can query system metadata or issue unprivileged requests.
- ✗
--protect-kernel-defaults=false
Why it's wrong here
Setting `--protect-kernel-defaults=false` tells the kubelet to ignore checks for kernel parameter settings such as `vm.overcommit_memory` and `net.ipv4.ip_forward`, and it does not enforce that those values follow the recommendations. CIS specifically requires this flag to be `true` so the kubelet refuses to start if the underlying host kernel tunables are not hardened, preventing containers from running on a host that is vulnerable to memory overcommit, IP forwarding abuse, or other kernel-level attacks.
- ✗
--read-only-port=10255
Why it's wrong here
Setting `--read-only-port=10255` enables the kubelet's legacy unauthenticated read-only port, allowing anyone who can reach that port to enumerate node state, running containers, and pod specifications without any authentication. The CIS Benchmark mandates `--read-only-port=0` to disable this port entirely, because any data exposed over this channel can aid lateral movement or reveal sensitive metadata that should only be accessible with kubelet credentials.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.