Courseiva
mediumMultiple Select

CKS Practice Question: Which two of the following are recommended by the…

Which two of the following are recommended by the CIS Kubernetes Benchmark? (Choose two.)

⚠ Common exam trap

CNCF often tests the misconception that NodePort services are suitable for internal cluster communication, but the trap is that NodePort is designed for external access and introduces unnecessary network exposure, while ClusterIP is the correct internal service type.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable anonymous authentication on the API server

The CIS Kubernetes Benchmark explicitly recommends disabling anonymous authentication on the API server to prevent unauthenticated access. Anonymous requests bypass all authentication checks and can lead to unauthorized cluster operations if RBAC is not properly scoped. Setting the `--anonymous-auth=false` flag on the API server ensures that only authenticated users can interact with the cluster.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use NodePort services for internal communication

    Why it's wrong here

    NodePort exposes a service on a static port on every node, making it reachable from outside the cluster. For internal communication, this unnecessarily widens the network attack surface and bypasses the more secure ClusterIP service, which is only reachable within the cluster. NodePort also introduces port conflict risks and requires additional firewall rules. The CIS Benchmark recommends restricting exposure and applying minimal networking principles, so NodePort is not recommended for internal service-to-service traffic.

  • ✗

    Enable the insecure port on the API server

    Why it's wrong here

    The API server's insecure port (default 8080) served unauthenticated HTTP requests, completely bypassing authentication and authorization controls. It was deprecated and removed in Kubernetes 1.20; running with it enabled violates CIS controls that require all API traffic to be authenticated and encrypted. Disabling it by not setting --insecure-port or setting it to 0 ensures every request goes through the secure HTTPS port with proper TLS and RBAC checks.

  • ✓

    Disable anonymous authentication on the API server

    Why this is correct

    Setting --anonymous-auth=false on the API server disables unauthenticated requests, so any request without valid credentials is rejected with HTTP 401. CIS Benchmark 1.2.1 specifically recommends this because anonymous access can allow unauthorized discovery of cluster metadata or exploitation of misconfigured RBAC. When enabled, the API server permits anonymous requests, which may be matched by overly permissive ClusterRoleBindings. Disabling it forces all clients to authenticate, reducing the risk of accidental exposure.

  • ✗

    Use the default service account for all pods

    Why it's wrong here

    Using the default service account for pods is discouraged because the account's token is automatically mounted into every pod and typically bound to default Kubernetes API permissions, which may be excessive or ill-defined. If a pod is compromised, an attacker can use this token to make authenticated API calls, potentially escalating privileges. CIS Benchmark 5.1 advises explicitly setting automountServiceAccountToken: false for the default account and creating dedicated service accounts with only the minimum RBAC permissions needed. This follows the principle of least privilege and reduces the blast radius of a container breakout.

  • ✓

    Enable audit logging on the API server

    Why this is correct

    Enabling audit logging via --audit-log-path configures the API server to record every request with metadata such as the user, source IP, and requested resource. CIS Benchmark 1.2.2 requires audit logs to be enabled to provide a tamper-evident trail for security investigations and compliance. Without audit logs, unauthorized or malicious API activities can go undetected. It is essential to set an appropriate audit policy to log verbose events at the Metadata or RequestResponse level for sensitive operations.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.