Courseiva
hardMultiple Select

CKS Practice Question: Which THREE of the following are valid methods to…

Which THREE of the following are valid methods to disable automount of service account tokens for a pod?

⚠ Common exam trap

CNCF often tests the distinction between the Pod spec field (`spec.automountServiceAccountToken`) and the ServiceAccount field, and candidates may incorrectly think that environment variables or API server flags can disable token mounting, when only the `automountServiceAccountToken` boolean field in the Pod or ServiceAccount spec is valid.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set automountServiceAccountToken: false in the ServiceAccount YAML

Setting `automountServiceAccountToken: false` in the ServiceAccount YAML disables automatic mounting of the service account token for all pods that use that ServiceAccount. This is a declarative way to prevent the Kubernetes API server from injecting the token volume into pods, which is a key security hardening step to reduce the attack surface from compromised pods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set --service-account-issuer flag on API server

    Why it's wrong here

    The --service-account-issuer flag on the API server sets the issuer identifier used in OIDC discovery and for validating the `iss` claim of bound service account tokens. It has no effect on whether kubelet mounts a token into pods. Auto-mounting is controlled exclusively by the `automountServiceAccountToken` field on the Pod spec or ServiceAccount object, not by API server startup flags.

  • ✗

    Set env: - name: KUBERNETES_SERVICE_ACCOUNT_TOKEN to false

    Why it's wrong here

    There is no supported environment variable named `KUBERNETES_SERVICE_ACCOUNT_TOKEN`; kubelet does not read such a variable to decide whether to mount a token. Service account tokens are delivered as files via the service account admission controller (or as a projected volume), not through an env var. Setting a similarly named env var in a container would be inert and cannot disable the default automount behavior.

  • ✓

    Set automountServiceAccountToken: false in the ServiceAccount YAML

    Why this is correct

    Setting `automountServiceAccountToken: false` in a ServiceAccount YAML disables automatic token mounting for every Pod that explicitly references that ServiceAccount. This is the standard way to revoke the default API credentials for workloads that use a dedicated service account. If a Pod sets `spec.automountServiceAccountToken` to true, that pod-level field overrides the ServiceAccount-level false.

  • ✓

    Set spec.automountServiceAccountToken: false in the Pod spec

    Why this is correct

    Setting `spec.automountServiceAccountToken: false` in the Pod spec turns off automatic token mounting for that individual Pod, taking precedence over the ServiceAccount's setting. This is useful when you want to run a specific workload without API credentials, even if the referenced ServiceAccount has the default automount enabled. The kubelet then omits the projected token volume for that Pod only.

  • ✓

    Use the 'default' service account with automount disabled

    Why this is correct

    Modifying the `default` ServiceAccount in a namespace to include `automountServiceAccountToken: false` affects all Pods that do not specify a `serviceAccountName` and therefore fall back to the `default` account. This is a powerful cluster-hardening measure because many workloads use the default account silently, and disabling automount for it prevents broad exposure of API credentials. Note that Pods explicitly using another ServiceAccount are unaffected; you can also create a separate `default` with automount disabled.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.