mediumMultiple Select
CKS Practice Question: Which TWO actions are part of the CIS Kubernetes…
Which TWO actions are part of the CIS Kubernetes Benchmark recommendations?
⚠ Common exam trap
CNCF often tests the misconception that disabling anonymous authentication is optional or that audit logging is only for debugging, when in fact both are mandatory hardening steps per the CIS Benchmark to prevent unauthorized access and ensure accountability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable audit logging on the API server
The CIS Kubernetes Benchmark recommends enabling audit logging on the API server to record all requests and responses, which is essential for security monitoring, forensics, and compliance. Audit logs capture the sequence of activities, including who performed an action, what resource was accessed, and the outcome, enabling detection of unauthorized or suspicious behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable audit logging on the API server
Why this is correct
Audit logging on the API server creates a chronological, tamper-evident record of every request, including the user, source IP, verb, resource, and response status. The CIS benchmark mandates this so that security teams can detect brute-force attacks, unauthorized privilege escalation, or policy violations after the fact and support forensic analysis in an incident. Without audit logs, cluster actions are effectively unobservable, making compliance audits and postmortems nearly impossible.
- ✗
Allow all service accounts to list secrets
Why it's wrong here
Giving every service account the ability to list secrets across all namespaces violates the principle of least privilege because secrets often contain database passwords, TLS keys, or cloud credentials. Any compromised pod, even a low-level workload, could then exfiltrate every secret in the cluster, likely leading to full cluster compromise. RBAC should restrict secret access to specific service accounts that genuinely need them, typically through targeted Role and RoleBinding objects.
- ✗
Expose the API server on port 8080
Why it's wrong here
The API server’s legacy port 8080 served traffic without TLS and, in older versions, authenticated differently, making it trivial for attackers on the network to send administrative requests or fetch sensitive data. While port 8080 is usually disabled or deprecated in modern Kubernetes, exposing it disregards the CIS recommendation to enable only the secure port 6443 with client-certificate authentication. Using the insecure port directly contradicts the benchmark’s requirement for secure, authenticated API access.
- ✓
Disable anonymous authentication on the API server
Why this is correct
Disabling anonymous authentication enforces the CIS rule that every API request must be tied to an authenticated identity, either a user or a service account. If anonymous access is left enabled, unauthenticated users can query the discovery endpoints and, if RBAC is misconfigured, might even access protected resources under the system:anonymous user. Setting --anonymous-auth=false closes that hole while still allowing legitimate health checks through explicitly exempted paths, but it is the foundation of a secure auth layer.
- ✗
Use HTTP for kubelet communication
Why it's wrong here
Communicating with kubelets over plain HTTP exposes sensitive node-level data such as pod manifests, container logs, and even secrets injected as environment variables or files. The kubelet’s secure port (10250) authenticates the API server and uses TLS to encrypt traffic, whereas the read-only port (10255) is unauthenticated and plaintext. Using HTTP for kubelet communication is specifically forbidden by the CIS benchmark because it leaves the entire node’s runtime state open to eavesdroppers and man-in-the-middle attacks.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO actions are recommended by the CIS Kubernetes Benchmark to secure the API server?
medium- ✓ A.Set --authorization-mode=RBAC
- B.Set --enable-admission-plugins=NodeRestriction
- C.Set --authorization-mode=AlwaysAllow
- D.Set --insecure-port=8080
- ✓ E.Set --anonymous-auth=false
Why A: Option A is correct because the CIS Kubernetes Benchmark recommends setting --authorization-mode=RBAC so that API requests are authorized through Kubernetes RBAC rather than permissive modes like AlwaysAllow, enforcing least-privilege access to cluster resources. Option E is correct because setting --anonymous-auth=false disables unauthenticated requests to the API server, ensuring that all callers must authenticate before any authorization decision is made. Option B is not among the two marked correct answers here, even though NodeRestriction is a legitimate admission plugin, because the question specifically asks for the two recommended actions marked as correct. Option C is wrong because --authorization-mode=AlwaysAllow permits all requests without authorization checks, directly contradicting CIS hardening guidance. Option D is wrong because --insecure-port=8080 exposes an unauthenticated, unencrypted HTTP endpoint on the API server, which the CIS Benchmark explicitly advises against.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.