Courseiva
Supply Chain Security →mediumMultiple Select

CKS Supply Chain Security Practice Question

Which TWO of the following are valid admission controllers in Kubernetes? (Select TWO)

⚠ Common exam trap

The CKS exam often tests the distinction between deprecated/removed features (like PodSecurityPolicy) and still-valid controllers, and the trap here is that candidates may confuse OPA as a built-in admission controller when it is actually an external policy engine integrated via webhooks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MutatingAdmissionWebhook

MutatingAdmissionWebhook, is a valid admission controller that intercepts API requests and can modify them before they are persisted. It is part of the dynamic admission control mechanism, allowing external webhooks to mutate objects. Option C, ImagePolicyWebhook, is also a valid admission controller that enforces image policy checks by querying an external webhook before admitting a pod, making it a key component for supply chain security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PodSecurityPolicy

    Why it's wrong here

    PodSecurityPolicy was a built-in admission controller, but it was deprecated in Kubernetes 1.21 and removed in 1.25, so it cannot be enabled on current clusters. It is tempting because it genuinely governed pod security via admission, and would be correct on legacy clusters before its removal.

  • ✓

    MutatingAdmissionWebhook

    Why this is correct

    MutatingAdmissionWebhook is a built-in admission controller that intercepts API requests after authentication and authorisation, invoking external webhooks to modify objects before persistence. It satisfies the stem's requirement for a valid admission controller, operating in the mutating phase alongside validating webhooks. Kubernetes enables it by default in the recommended admission plugin set.

  • ✓

    ImagePolicyWebhook

    Why this is correct

    ImagePolicyWebhook is a genuine Kubernetes admission controller that queries an external HTTP endpoint to validate pod images against policy. It satisfies the validity constraint by operating at admission time, gating workloads before they are persisted to etcd.

  • ✗

    AdmissionReview

    Why it's wrong here

    AdmissionReview is the API request/response payload structure exchanged between the API server and webhooks, not an admission controller itself. It is tempting because it appears throughout admission webhook configuration, and would be the right answer if the question asked about the data format webhooks receive and return.

  • ✗

    OPA

    Why it's wrong here

    OPA is a general-purpose policy engine, not a Kubernetes admission controller; it requires the Gatekeeper project to integrate as a validating webhook. It is tempting because it enforces admission-style policy, and would be correct if the question asked which external policy framework underpins Gatekeeper.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.