mediumMultiple Select
CKS Practice Question: Which TWO of the following are CIS Benchmark…
Which TWO of the following are CIS Benchmark recommendations for securing the API server?
⚠ Common exam trap
CNCF often tests the distinction between deprecated/insecure features (like the insecure port or disabling TLS) and the actual CIS-recommended secure defaults, tempting candidates to select options that sound like hardening but are actually anti-patterns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable anonymous authentication
The CIS Benchmark for Kubernetes recommends disabling anonymous authentication to ensure that all requests to the API server are authenticated. By setting the `--anonymous-auth=false` flag on the kube-apiserver, unauthenticated requests are rejected, which prevents anonymous users from accessing the cluster. This is a fundamental security hardening step to enforce identity verification for every API call.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the insecure port (--insecure-port)
Why it's wrong here
CIS recommends setting the kube-apiserver's --insecure-port to 0 to disable the legacy HTTP endpoint. This port serves the API without TLS or authentication, exposing cluster operations to anyone who can reach it. Use the secure port 6443 with client certificate authentication instead.
- ✓
Disable anonymous authentication
Why this is correct
CIS controls for the API server and kubelet require --anonymous-auth=false so every request must be authenticated. Leaving anonymous access enabled allows unauthenticated users to query or mutate cluster state if RBAC is misconfigured. Disabling anonymous authentication is a core hardening step and is directly recommended by the benchmark.
- ✓
Enable audit logging
Why this is correct
CIS requires audit logging to be enabled on the API server with flags such as --audit-log-path and --audit-log-maxage. Audit logs provide an immutable trail of API calls, making it possible to detect unauthorized activity and meet compliance requirements. The benchmark also recommends setting an audit policy to capture important actions rather than logging everything.
- ✗
Use ABAC mode for authorization
Why it's wrong here
CIS does not recommend ABAC as the authorization mode because its policy files are monolithic and difficult to maintain, review, or apply at scale. The benchmark specifically directs operators to ensure the authorization-mode includes RBAC, which supports granular, role-based permissions and easier auditing. ABAC changes require restarting the API server and offer no administrative separation.
- ✗
Disable TLS
Why it's wrong here
Disabling TLS would expose all Kubernetes API and component traffic to interception and tampering. CIS mandates that TLS be enabled for kube-apiserver and etcd, preferably with certificates signed by a trusted CA and strong cipher suites. The secure port must be the only API endpoint, with all communication encrypted in transit.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.