CKS Minimize Microservice Vulnerabilities Practice Question
Which TWO of the following are valid Rego keywords used in OPA policies for Gatekeeper? (Select TWO)
⚠ Common exam trap
Gatekeeper often tests the distinction between Rego language keywords (like `input` and `data`) and common rule names (like `violation`, `allow`, `deny`) that are not part of the language specification. Candidates mistakenly treat custom rule names as keywords.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
input
In Rego, `input` and `data` are reserved keywords. `input` refers to the incoming document (e.g., the admission review request in Gatekeeper), and `data` refers to the global data document containing external data. `deny` is not a keyword but a common rule name used to trigger denial; `violation` and `allow` are also custom rule names. Therefore, the correct answer is options C and D.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
violation
Why it's wrong here
`violation` is a common rule name required by Gatekeeper's constraint template contract, but it is not a Rego reserved keyword. In a Gatekeeper template, you must define a set of violations, but this is an interface requirement, not a language feature. Rego would allow you to name the rule anything; Gatekeeper just expects a specific name to process it. Therefore, it's a naming convention, not a language keyword.
- ✗
allow
Why it's wrong here
Similarly, `allow` is a user-defined rule name that typically evaluates to true to grant access, but Rego itself does not reserve or automatically evaluate it. The language has no built-in `allow` keyword; the rule only works because we write and call it explicitly. As a convention, it is semantically meaningful to the policy author, but not syntactically special to the Rego parser.
- ✓
input
Why this is correct
`input` is a reserved Rego symbol that refers to the complete input document passed to the query, e.g., an admission review request in Kubernetes. It is the root for all input data, accessed like `input.request.userInfo`. Because it is defined by the language as the root of the query input, it cannot be used as a regular rule name. That makes it a valid Rego keyword, parallel to `data`.
- ✓
data
Why this is correct
`data` is a reserved Rego symbol representing the global data document—the full set of external data loaded into OPA, such as Kubernetes objects or custom structured stores. You reference it with the `data` prefix (e.g., `data.namespaces`). Because it is a language-defined reference, it can never be redeclared as a rule name. This is why it is a valid keyword, not a naming convention.
- ✗
deny
Why it's wrong here
The word `deny` is frequently chosen as the name of a rule in OPA policies to collect policy violations, but Rego imposes no special status on it. Unlike reserved words like `package` or `import`, `deny` can be used as a regular rule name, and the language does not automatically treat it as a denial. Its interpretive meaning arises solely from how policy authors and external systems consume the rule's results, so it is not a Rego keyword.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.