mediumMultiple Select
CKS Practice Question: Which two of the following are recommended by the…
Which two of the following are recommended by the CIS Kubernetes Benchmark? (Choose two.)
⚠ Common exam trap
CNCF often tests the misconception that NodePort services are suitable for internal cluster communication, but the trap is that NodePort is designed for external access and introduces unnecessary network exposure, while ClusterIP is the correct internal service type.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable anonymous authentication on the API server
The CIS Kubernetes Benchmark explicitly recommends disabling anonymous authentication on the API server to prevent unauthenticated access. Anonymous requests bypass all authentication checks and can lead to unauthorized cluster operations if RBAC is not properly scoped. Setting the `--anonymous-auth=false` flag on the API server ensures that only authenticated users can interact with the cluster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use NodePort services for internal communication
Why it's wrong here
NodePort exposes a service on a static port on every node, making it reachable from outside the cluster. For internal communication, this unnecessarily widens the network attack surface and bypasses the more secure ClusterIP service, which is only reachable within the cluster. NodePort also introduces port conflict risks and requires additional firewall rules. The CIS Benchmark recommends restricting exposure and applying minimal networking principles, so NodePort is not recommended for internal service-to-service traffic.
- ✗
Enable the insecure port on the API server
Why it's wrong here
The API server's insecure port (default 8080) served unauthenticated HTTP requests, completely bypassing authentication and authorization controls. It was deprecated and removed in Kubernetes 1.20; running with it enabled violates CIS controls that require all API traffic to be authenticated and encrypted. Disabling it by not setting --insecure-port or setting it to 0 ensures every request goes through the secure HTTPS port with proper TLS and RBAC checks.
- ✓
Disable anonymous authentication on the API server
Why this is correct
Setting --anonymous-auth=false on the API server disables unauthenticated requests, so any request without valid credentials is rejected with HTTP 401. CIS Benchmark 1.2.1 specifically recommends this because anonymous access can allow unauthorized discovery of cluster metadata or exploitation of misconfigured RBAC. When enabled, the API server permits anonymous requests, which may be matched by overly permissive ClusterRoleBindings. Disabling it forces all clients to authenticate, reducing the risk of accidental exposure.
- ✗
Use the default service account for all pods
Why it's wrong here
Using the default service account for pods is discouraged because the account's token is automatically mounted into every pod and typically bound to default Kubernetes API permissions, which may be excessive or ill-defined. If a pod is compromised, an attacker can use this token to make authenticated API calls, potentially escalating privileges. CIS Benchmark 5.1 advises explicitly setting automountServiceAccountToken: false for the default account and creating dedicated service accounts with only the minimum RBAC permissions needed. This follows the principle of least privilege and reduces the blast radius of a container breakout.
- ✓
Enable audit logging on the API server
Why this is correct
Enabling audit logging via --audit-log-path configures the API server to record every request with metadata such as the user, source IP, and requested resource. CIS Benchmark 1.2.2 requires audit logs to be enabled to provide a tamper-evident trail for security investigations and compliance. Without audit logs, unauthorized or malicious API activities can go undetected. It is essential to set an appropriate audit policy to log verbose events at the Metadata or RequestResponse level for sensitive operations.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.