easyMultiple Select
CKS Practice Question: Which TWO of the following flags are used to…
Which TWO of the following flags are used to secure the kubelet?
⚠ Common exam trap
CNCF often tests the distinction between kubelet flags and API server flags, so the trap here is that candidates may confuse `--authorization-mode=RBAC` or `--audit-log-path` as kubelet security settings when they are actually API server parameters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--protect-kernel-defaults
The `--protect-kernel-defaults` flag is used to secure the kubelet by ensuring that kernel tunable parameters (e.g., `vm.overcommit_memory`, `kernel.panic`) are set to safe values. If the kernel defaults are not properly configured, the kubelet will fail to start, preventing insecure kernel settings from being used. This flag is part of the kubelet's security hardening measures, as recommended by the CIS Kubernetes Benchmark.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
--protect-kernel-defaults
Why this is correct
--protect-kernel-defaults is a kubelet flag that enforces kernel hardening by refusing to apply sysctls that would alter sensitive kernel parameters like net.ipv4.tcp_syncookies or kernel.shmmax. It ensures the node's kernel stays in a secure default state, and the kubelet will fail to start or reject pod updates if a disallowed sysctl is requested. This is a key control for reducing the attack surface on worker nodes, especially in multi-tenant clusters.
- ✓
--anonymous-auth=false
Why this is correct
--anonymous-auth=false is a kubelet flag that disables anonymous HTTP requests to the kubelet's endpoints, such as /pods, /exec, and /healthz. Without this flag, the kubelet might allow unauthenticated connections, potentially exposing container logs or allowing remote command execution. Setting it to false forces all requests to present valid client certificates or other authentication credentials, ensuring only authenticated users or the API server can interact with the kubelet.
- ✗
--enable-admission-plugins
Why it's wrong here
--enable-admission-plugins is a kube-apiserver flag used to activate admission controllers like PodSecurityPolicy, ResourceQuota, or ValidatingAdmissionPolicy, which inspect and mutate requests before they are persisted. This flag has no effect on the kubelet process itself; admission plugins run in the API server's request pipeline, not on nodes. Therefore, while it secures the control plane, it cannot be used to secure the kubelet.
- ✗
--audit-log-path
Why it's wrong here
--audit-log-path is a kube-apiserver flag that enables audit logging by specifying a file path where the API server writes a record of every request, including who made it and what action was performed. The kubelet does not have an audit log convention; it emits events to the system journal or its own kubelet.log. Thus, this flag is exclusively for the API server and does nothing to harden the kubelet.
- ✗
--authorization-mode=RBAC
Why it's wrong here
--authorization-mode=RBAC is a kube-apiserver flag that configures the API server to authorize requests using Role-Based Access Control, mapping users and groups to permissions via roles and role bindings. Although the kubelet has a similar-sounding flag, it only accepts values like AlwaysAllow or Webhook and does not support RBAC mode directly; node authorization is handled by the API server's Node and RBAC modes. As a result, this flag is not a kubelet security control and is incorrect for this question.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.