CKS System Hardening Practice Question
Which TWO of the following are effective methods to harden the kubelet against unauthorized access?
⚠ Common exam trap
The kubelet's own API endpoint is protected by authentication and authorization settings such as --anonymous-auth=false, --authentication-token-webhook, --client-ca-file, and --authorization-mode=Webhook. NodeRestriction limits a compromised kubelet's API-server access but does not harden the kubelet itself against incoming unauthorized requests.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable --authentication-token-webhook
To harden the kubelet's own HTTPS endpoint, enable --authentication-token-webhook to validate bearer tokens via the Kubernetes TokenReview API, and configure --client-ca-file with --tls-cert-file to require and validate client certificates. NodeRestriction is an admission controller that limits what the kubelet can modify in the API server; it does not protect the kubelet endpoint from unauthorized access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set --read-only-port=10255
Why it's wrong here
--read-only-port=10255 opens an unauthenticated read-only endpoint exposing pod and node metadata; hardening requires setting it to 0. It is tempting because read-only access appears harmless, and it would suit a deliberately monitored honeypot or a fully air-gapped test node with no sensitive workloads.
- ✓
Enable --authentication-token-webhook
Why this is correct
Enabling --authentication-token-webhook makes the kubelet validate bearer tokens against the API server's TokenReview endpoint, so only authenticated, authorised identities can reach the kubelet API. This closes anonymous or unauthenticated access to the kubelet's HTTPS endpoint.
- ✗
Enable the NodeRestriction admission controller
Why it's wrong here
NodeRestriction is an admission controller that restricts which Node and Pod objects a kubelet may modify via the API server. It reduces the impact of a compromised node but does not protect the kubelet's own API endpoint from unauthorized access.
- ✓
Configure --client-ca-file and --tls-cert-file to require client certificates
Why this is correct
Configuring --client-ca-file and --tls-cert-file forces the kubelet to require and validate client certificates for all incoming requests, ensuring only authenticated clients can access the kubelet API. This is a strong authentication mechanism that effectively hardens against unauthorized access.
- ✗
Set --anonymous-auth=true
Why it's wrong here
Setting --anonymous-auth=true permits unauthenticated requests to the kubelet API, which is precisely the exposure hardening must eliminate. It is tempting because it removes authentication friction during debugging, and it would be acceptable only in an isolated lab where no untrusted network path reaches port 10250.
Go deeper
Related to this question
Learn chapter
Kubernetes Security Fundamentals
Key term
OPA Gatekeeper
OPA Gatekeeper is a Kubernetes admission controller that enforces custom security and compliance policies on resources before they are created or updated in a cluster.
Key term
Node Restriction
A Kubernetes admission controller that limits what a kubelet can modify on its own node to prevent privilege escalation and unauthorized access.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.