Courseiva
mediumMultiple Select

CKS Practice Question: Which TWO admission plugins are recommended to be…

Which TWO admission plugins are recommended to be enabled for security hardening?

⚠ Common exam trap

CNCF often tests the distinction between plugins that are 'enabled by default' (like NamespaceLifecycle) versus those that are specifically 'recommended for security hardening' (like NodeRestriction and PodSecurity), causing candidates to pick default plugins that are not security-focused.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NodeRestriction

NodeRestriction is correct because it limits the Node object modifications a kubelet can make, preventing compromised nodes from modifying other nodes or escalating privileges. PodSecurity is correct because it enforces Pod Security Standards (baseline, restricted) via admission, replacing the deprecated PodSecurityPolicy with a built-in, stable mechanism for controlling pod security contexts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AlwaysPullImages

    Why it's wrong here

    AlwaysPullImages is a valid security control that forces the kubelet to re-pull an image from the registry each time instead of reusing a locally cached copy, which can help prevent execution of a previously present, untrusted image. However, it is not one of the two admission plugins universally recommended for core cluster hardening, because it adds significant latency and availability concerns and does not directly restrict node behavior or enforce pod-level security standards.

  • ✓

    NodeRestriction

    Why this is correct

    NodeRestriction is a core recommended admission plugin that limits what a kubelet may modify by ensuring a node can only alter its own Node object, its owned labels, and status fields, while preventing it from writing to other nodes or using arbitrary identities. It works tightly with the Node authorizer and prevents a compromised kubelet from escalating privileges by tainting or labeling other nodes or by requesting scoped certificates for a different node name, making it essential for node-level least privilege.

  • ✗

    NamespaceLifecycle

    Why it's wrong here

    NamespaceLifecycle is an admission plugin that stops creation of objects in a namespace that is terminating and prevents deletion of the built-in kube-system and kube-public namespaces, but it is primarily aimed at namespace lifecycle consistency rather than security hardening. It does not constrain pod capabilities, node access, or authorization boundaries, so it is not considered one of the two recommended security admission plugins. A determined attacker is unlikely to gain privilege escalation from bypassing namespace deletion rules, unlike with pod security or node restriction failures.

  • ✓

    PodSecurity

    Why this is correct

    PodSecurity is the built-in admission plugin that enforces the Pod Security Standards (privileged, baseline, restricted) using namespace labels, and it replaces the deprecated PodSecurityPolicy. It evaluates every pod at creation time and rejects configurations like privileged containers, dangerous capabilities, or hostPath mounts, thereby reducing the blast radius of a compromised workload. Because it directly enforces least privilege for user workloads, it is one of the two premier admission plugins recommended for cluster hardening.

  • ✗

    DefaultStorageClass

    Why it's wrong here

    DefaultStorageClass is an admission plugin that automatically sets a default StorageClass on any PersistentVolumeClaim that does not request a specific class, so it is purely a convenience defaulting mechanism. It has no influence on pod security, node authorization, or any security-related admission decision, as it neither blocks nor restricts any object based on privileges or policy. This makes it entirely irrelevant to the recommended set of security-focused admission plugins for a hardened Kubernetes API server.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.