mediumMultiple Select
CKS Practice Question: Which TWO admission plugins are recommended to be…
Which TWO admission plugins are recommended to be enabled for security hardening?
⚠ Common exam trap
CNCF often tests the distinction between plugins that are 'enabled by default' (like NamespaceLifecycle) versus those that are specifically 'recommended for security hardening' (like NodeRestriction and PodSecurity), causing candidates to pick default plugins that are not security-focused.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NodeRestriction
NodeRestriction is correct because it limits the Node object modifications a kubelet can make, preventing compromised nodes from modifying other nodes or escalating privileges. PodSecurity is correct because it enforces Pod Security Standards (baseline, restricted) via admission, replacing the deprecated PodSecurityPolicy with a built-in, stable mechanism for controlling pod security contexts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AlwaysPullImages
Why it's wrong here
AlwaysPullImages is a valid security control that forces the kubelet to re-pull an image from the registry each time instead of reusing a locally cached copy, which can help prevent execution of a previously present, untrusted image. However, it is not one of the two admission plugins universally recommended for core cluster hardening, because it adds significant latency and availability concerns and does not directly restrict node behavior or enforce pod-level security standards.
- ✓
NodeRestriction
Why this is correct
NodeRestriction is a core recommended admission plugin that limits what a kubelet may modify by ensuring a node can only alter its own Node object, its owned labels, and status fields, while preventing it from writing to other nodes or using arbitrary identities. It works tightly with the Node authorizer and prevents a compromised kubelet from escalating privileges by tainting or labeling other nodes or by requesting scoped certificates for a different node name, making it essential for node-level least privilege.
- ✗
NamespaceLifecycle
Why it's wrong here
NamespaceLifecycle is an admission plugin that stops creation of objects in a namespace that is terminating and prevents deletion of the built-in kube-system and kube-public namespaces, but it is primarily aimed at namespace lifecycle consistency rather than security hardening. It does not constrain pod capabilities, node access, or authorization boundaries, so it is not considered one of the two recommended security admission plugins. A determined attacker is unlikely to gain privilege escalation from bypassing namespace deletion rules, unlike with pod security or node restriction failures.
- ✓
PodSecurity
Why this is correct
PodSecurity is the built-in admission plugin that enforces the Pod Security Standards (privileged, baseline, restricted) using namespace labels, and it replaces the deprecated PodSecurityPolicy. It evaluates every pod at creation time and rejects configurations like privileged containers, dangerous capabilities, or hostPath mounts, thereby reducing the blast radius of a compromised workload. Because it directly enforces least privilege for user workloads, it is one of the two premier admission plugins recommended for cluster hardening.
- ✗
DefaultStorageClass
Why it's wrong here
DefaultStorageClass is an admission plugin that automatically sets a default StorageClass on any PersistentVolumeClaim that does not request a specific class, so it is purely a convenience defaulting mechanism. It has no influence on pod security, node authorization, or any security-related admission decision, as it neither blocks nor restricts any object based on privileges or policy. This makes it entirely irrelevant to the recommended set of security-focused admission plugins for a hardened Kubernetes API server.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Policy Enforcement and Admission Controllers
Key term
Admission Controllers
Admission controllers are plugins that intercept and process requests to the Kubernetes API server after authentication and authorization, but before the request is persisted, allowing policies to be enforced on objects being created, modified, or deleted.
Key term
Pod Security Standards
Pod Security Standards are a set of predefined Kubernetes policies that control the security context of pods to prevent privilege escalation and enforce least privilege.
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.