Courseiva
System Hardening →hardMultiple Select

CKS System Hardening Practice Question

Which TWO of the following are effective methods to harden the kubelet against unauthorized access?

⚠ Common exam trap

The kubelet's own API endpoint is protected by authentication and authorization settings such as --anonymous-auth=false, --authentication-token-webhook, --client-ca-file, and --authorization-mode=Webhook. NodeRestriction limits a compromised kubelet's API-server access but does not harden the kubelet itself against incoming unauthorized requests.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable --authentication-token-webhook

To harden the kubelet's own HTTPS endpoint, enable --authentication-token-webhook to validate bearer tokens via the Kubernetes TokenReview API, and configure --client-ca-file with --tls-cert-file to require and validate client certificates. NodeRestriction is an admission controller that limits what the kubelet can modify in the API server; it does not protect the kubelet endpoint from unauthorized access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set --read-only-port=10255

    Why it's wrong here

    --read-only-port=10255 opens an unauthenticated read-only endpoint exposing pod and node metadata; hardening requires setting it to 0. It is tempting because read-only access appears harmless, and it would suit a deliberately monitored honeypot or a fully air-gapped test node with no sensitive workloads.

  • ✓

    Enable --authentication-token-webhook

    Why this is correct

    Enabling --authentication-token-webhook makes the kubelet validate bearer tokens against the API server's TokenReview endpoint, so only authenticated, authorised identities can reach the kubelet API. This closes anonymous or unauthenticated access to the kubelet's HTTPS endpoint.

  • ✗

    Enable the NodeRestriction admission controller

    Why it's wrong here

    NodeRestriction is an admission controller that restricts which Node and Pod objects a kubelet may modify via the API server. It reduces the impact of a compromised node but does not protect the kubelet's own API endpoint from unauthorized access.

  • ✓

    Configure --client-ca-file and --tls-cert-file to require client certificates

    Why this is correct

    Configuring --client-ca-file and --tls-cert-file forces the kubelet to require and validate client certificates for all incoming requests, ensuring only authenticated clients can access the kubelet API. This is a strong authentication mechanism that effectively hardens against unauthorized access.

  • ✗

    Set --anonymous-auth=true

    Why it's wrong here

    Setting --anonymous-auth=true permits unauthenticated requests to the kubelet API, which is precisely the exposure hardening must eliminate. It is tempting because it removes authentication friction during debugging, and it would be acceptable only in an isolated lab where no untrusted network path reaches port 10250.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.