Courseiva
Supply Chain Security →hardMultiple Select

Admission Controller Order: Why Mutating Webhooks Run Before Validating

Which THREE of the following are correct statements about Kubernetes admission controllers in the context of supply chain security? (Select 3)

⚠ Common exam trap

A common misconception is that MutatingAdmissionWebhook is limited to pods, when in fact it can intercept and mutate any Kubernetes resource type. Another is that OPA/Gatekeeper relies on mutating webhooks, whereas its primary enforcement mechanism is validating webhooks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Admission controllers are executed in a specific order that can affect the final state of the resource

Admission controllers are executed in a specific order: mutating controllers run first, then validating controllers. This ordering is critical because a mutating webhook can modify the resource before a validating webhook evaluates it, potentially bypassing intended policies if the order is not carefully managed. The Kubernetes API server processes admission controllers sequentially based on the order defined in the API server flags or the built-in chain, which directly affects the final resource state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Admission controllers are executed in a specific order that can affect the final state of the resource

    Why this is correct

    The order of admission controllers can impact the final resource, especially when mutating and validating are mixed.

  • ✓

    ValidatingAdmissionWebhook can be used to enforce policies like requiring all images to be signed

    Why this is correct

    A ValidatingAdmissionWebhook can validate that images have signatures or meet other criteria.

  • ✗

    MutatingAdmissionWebhook can only modify pods, not other resources

    Why it's wrong here

    MutatingAdmissionWebhooks can modify any resource type, not just pods.

  • ✓

    ImagePolicyWebhook is used to validate container images against an external policy

    Why this is correct

    ImagePolicyWebhook checks images against a policy service and can deny admission if the image fails checks.

  • ✗

    OPA/Gatekeeper uses MutatingAdmissionWebhook to enforce policies

    Why it's wrong here

    OPA/Gatekeeper primarily uses ValidatingAdmissionWebhook, though it can also use mutating webhooks. It does not rely solely on mutating webhooks.

Go deeper

Related to this question

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.