Courseiva
Cluster Hardening →hardMultiple Select

CKS Cluster Hardening Practice Question

Which THREE of the following are valid methods to enforce pod security standards in a Kubernetes cluster?

⚠ Common exam trap

CNCF often tests the distinction between auditing tools (like kube-bench) and admission controllers that enforce policies at runtime, leading candidates to mistakenly select kube-bench as an enforcement method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Kyverno policy engine

Kyverno is a Kubernetes-native policy engine that can enforce pod security standards by validating, mutating, and generating resources based on policies written as Kubernetes custom resources. It integrates with the Kubernetes API server via dynamic admission webhooks, allowing it to reject non-compliant pod specs before they are persisted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use Kyverno policy engine

    Why this is correct

    Kyverno is a Kubernetes-native policy engine that operates as a dynamic admission controller, intercepting AdmissionReview requests during resource creation and modification. It enforces pod security by evaluating policies written as custom Kubernetes resources, which can include built-in rules aligned with the Pod Security Standards. Unlike static analysis or auditing, Kyverno actively rejects or mutates non-compliant pod manifests before they are persisted in etcd, making it a valid enforcement method.

  • ✗

    Run kube-bench on the cluster

    Why it's wrong here

    kube-bench is a compliance assessment tool that runs a series of automated checks against a cluster to verify adherence to the CIS Kubernetes Benchmark. It inspects configuration files, API server flags, and node settings, generating a report of pass/fail findings, but it does not register as an admission controller or otherwise intercept API requests. Consequently, kube-bench can only highlight weaknesses after the fact and cannot prevent a non-compliant pod from being created, so it is not an enforcement mechanism.

  • ✗

    Manual review of all pod specs

    Why it's wrong here

    Manual review of every pod spec relies on human inspection of manifests or live resources, which is not only unscalable but also fails to provide a technical control that blocks non-compliant pods at creation time. In a dynamic cluster with continuous deployments, automated workloads, or many developers, manual review is error-prone and cannot intercept API requests before a pod is scheduled. Since it lacks integration with the admission control flow, this approach is neither reliable nor enforceable, making it an invalid method for enforcing pod security.

  • ✓

    Use Open Policy Agent (OPA) with Gatekeeper

    Why this is correct

    OPA Gatekeeper is an external admission controller that integrates the Open Policy Agent with Kubernetes through a validating webhook. It evaluates policies written in Rego against incoming AdmissionReview objects and can either admit or deny requests based on constraints defined as Kubernetes custom resources. While Gatekeeper also offers an audit feature, its core enforcement is synchronous and occurs before a pod is persisted, making it a valid and widely adopted enforcement method.

  • ✓

    Enable PodSecurity admission plugin

    Why this is correct

    The PodSecurity admission plugin is a native Kubernetes admission controller that evaluates pods against the Pod Security Standards (privileged, baseline, and restricted). It operates in three configurable modes—enforce, audit, and warn—defined via labels on namespaces, and in enforce mode it rejects pod creation that does not match the specified standard. Because it is built into the API server, it requires no external components and directly blocks non-compliant pods, making it a valid enforcement method.

Go deeper

Related to this question

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.