hardMultiple Select
CKS Practice Question: Which THREE of the following are valid methods to…
Which THREE of the following are valid methods to disable automount of service account tokens for a pod?
⚠ Common exam trap
CNCF often tests the distinction between the Pod spec field (`spec.automountServiceAccountToken`) and the ServiceAccount field, and candidates may incorrectly think that environment variables or API server flags can disable token mounting, when only the `automountServiceAccountToken` boolean field in the Pod or ServiceAccount spec is valid.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set automountServiceAccountToken: false in the ServiceAccount YAML
Setting `automountServiceAccountToken: false` in the ServiceAccount YAML disables automatic mounting of the service account token for all pods that use that ServiceAccount. This is a declarative way to prevent the Kubernetes API server from injecting the token volume into pods, which is a key security hardening step to reduce the attack surface from compromised pods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set --service-account-issuer flag on API server
Why it's wrong here
The --service-account-issuer flag on the API server sets the issuer identifier used in OIDC discovery and for validating the `iss` claim of bound service account tokens. It has no effect on whether kubelet mounts a token into pods. Auto-mounting is controlled exclusively by the `automountServiceAccountToken` field on the Pod spec or ServiceAccount object, not by API server startup flags.
- ✗
Set env: - name: KUBERNETES_SERVICE_ACCOUNT_TOKEN to false
Why it's wrong here
There is no supported environment variable named `KUBERNETES_SERVICE_ACCOUNT_TOKEN`; kubelet does not read such a variable to decide whether to mount a token. Service account tokens are delivered as files via the service account admission controller (or as a projected volume), not through an env var. Setting a similarly named env var in a container would be inert and cannot disable the default automount behavior.
- ✓
Set automountServiceAccountToken: false in the ServiceAccount YAML
Why this is correct
Setting `automountServiceAccountToken: false` in a ServiceAccount YAML disables automatic token mounting for every Pod that explicitly references that ServiceAccount. This is the standard way to revoke the default API credentials for workloads that use a dedicated service account. If a Pod sets `spec.automountServiceAccountToken` to true, that pod-level field overrides the ServiceAccount-level false.
- ✓
Set spec.automountServiceAccountToken: false in the Pod spec
Why this is correct
Setting `spec.automountServiceAccountToken: false` in the Pod spec turns off automatic token mounting for that individual Pod, taking precedence over the ServiceAccount's setting. This is useful when you want to run a specific workload without API credentials, even if the referenced ServiceAccount has the default automount enabled. The kubelet then omits the projected token volume for that Pod only.
- ✓
Use the 'default' service account with automount disabled
Why this is correct
Modifying the `default` ServiceAccount in a namespace to include `automountServiceAccountToken: false` affects all Pods that do not specify a `serviceAccountName` and therefore fall back to the `default` account. This is a powerful cluster-hardening measure because many workloads use the default account silently, and disabling automount for it prevents broad exposure of API credentials. Note that Pods explicitly using another ServiceAccount are unaffected; you can also create a separate `default` with automount disabled.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.