CKS Cluster Hardening Practice Question
Which THREE of the following are valid methods to enforce pod security standards in a Kubernetes cluster?
⚠ Common exam trap
CNCF often tests the distinction between auditing tools (like kube-bench) and admission controllers that enforce policies at runtime, leading candidates to mistakenly select kube-bench as an enforcement method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Kyverno policy engine
Kyverno is a Kubernetes-native policy engine that can enforce pod security standards by validating, mutating, and generating resources based on policies written as Kubernetes custom resources. It integrates with the Kubernetes API server via dynamic admission webhooks, allowing it to reject non-compliant pod specs before they are persisted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Kyverno policy engine
Why this is correct
Kyverno is a Kubernetes-native policy engine that operates as a dynamic admission controller, intercepting AdmissionReview requests during resource creation and modification. It enforces pod security by evaluating policies written as custom Kubernetes resources, which can include built-in rules aligned with the Pod Security Standards. Unlike static analysis or auditing, Kyverno actively rejects or mutates non-compliant pod manifests before they are persisted in etcd, making it a valid enforcement method.
- ✗
Run kube-bench on the cluster
Why it's wrong here
kube-bench is a compliance assessment tool that runs a series of automated checks against a cluster to verify adherence to the CIS Kubernetes Benchmark. It inspects configuration files, API server flags, and node settings, generating a report of pass/fail findings, but it does not register as an admission controller or otherwise intercept API requests. Consequently, kube-bench can only highlight weaknesses after the fact and cannot prevent a non-compliant pod from being created, so it is not an enforcement mechanism.
- ✗
Manual review of all pod specs
Why it's wrong here
Manual review of every pod spec relies on human inspection of manifests or live resources, which is not only unscalable but also fails to provide a technical control that blocks non-compliant pods at creation time. In a dynamic cluster with continuous deployments, automated workloads, or many developers, manual review is error-prone and cannot intercept API requests before a pod is scheduled. Since it lacks integration with the admission control flow, this approach is neither reliable nor enforceable, making it an invalid method for enforcing pod security.
- ✓
Use Open Policy Agent (OPA) with Gatekeeper
Why this is correct
OPA Gatekeeper is an external admission controller that integrates the Open Policy Agent with Kubernetes through a validating webhook. It evaluates policies written in Rego against incoming AdmissionReview objects and can either admit or deny requests based on constraints defined as Kubernetes custom resources. While Gatekeeper also offers an audit feature, its core enforcement is synchronous and occurs before a pod is persisted, making it a valid and widely adopted enforcement method.
- ✓
Enable PodSecurity admission plugin
Why this is correct
The PodSecurity admission plugin is a native Kubernetes admission controller that evaluates pods against the Pod Security Standards (privileged, baseline, and restricted). It operates in three configurable modes—enforce, audit, and warn—defined via labels on namespaces, and in enforce mode it rejects pod creation that does not match the specified standard. Because it is built into the API server, it requires no external components and directly blocks non-compliant pods, making it a valid enforcement method.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Policy Enforcement and Admission Controllers
Key term
Pod Security Standards
Pod Security Standards are a set of predefined Kubernetes policies that control the security context of pods to prevent privilege escalation and enforce least privilege.
Key term
Pod Security Admission
Pod Security Admission is a Kubernetes feature that enforces security standards on pods at creation time to prevent running containers with dangerous privileges.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.