mediumMultiple Select
CKS Practice Question: Which TWO resources can be used to implement RBAC…
Which TWO resources can be used to implement RBAC in Kubernetes?
⚠ Common exam trap
CNCF often tests the distinction between RBAC authorization resources (Role/ClusterRole) and other Kubernetes objects that deal with security but serve different purposes, such as NetworkPolicy (network segmentation) or PodSecurityPolicy (pod security constraints), leading candidates to confuse authorization with other security controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ClusterRole
A is correct because ClusterRole is a Kubernetes RBAC resource that defines a set of permissions (rules) that are not namespaced, allowing cluster-wide access. RBAC in Kubernetes uses Role and ClusterRole objects to specify allowed verbs (e.g., get, list, create) on resources (e.g., pods, secrets), and they are bound to subjects via RoleBinding or ClusterRoleBinding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ClusterRole
Why this is correct
ClusterRole is a Kubernetes RBAC object that defines permissions, such as verbs (get, list, create) on resources (pods, deployments), but unlike Role it is cluster-scoped. It can grant cluster-wide access when bound via a ClusterRoleBinding, or it can be reused in a single namespace by binding it with a RoleBinding, whose effective permissions are scoped to that namespace. ClusterRole is the correct answer because it is one of the two primary RBAC rule resources, alongside Role.
- ✗
NetworkPolicy
Why it's wrong here
NetworkPolicy is a namespaced Kubernetes resource that controls traffic flow between pods, namespaces, and external endpoints at the network layer (L3/L4). It is completely unrelated to authorization of API requests; RBAC restricts what a user or service account can do with the Kubernetes API, not which pods can communicate with each other. Therefore, NetworkPolicy cannot implement RBAC.
- ✗
PodSecurityPolicy
Why it's wrong here
PodSecurityPolicy was an admission controller resource that enforced security constraints on pod specifications, such as privileged mode, host namespaces, and allowed capabilities. It never defined user permissions or API access rules, so it was not a component of RBAC. Moreover, PodSecurityPolicy was deprecated in Kubernetes 1.21 and removed in 1.25, making it even less relevant to current RBAC implementations.
- ✗
ServiceAccount
Why it's wrong here
ServiceAccount is an identity object used by pods to authenticate to the Kubernetes API server. While RBAC involves granting permissions to service accounts through Roles or ClusterRoles and their bindings, the ServiceAccount resource itself contains no permission rules—it merely represents a non-human principal. Thus, a ServiceAccount is a subject for authorization, not an RBAC resource that defines permissions.
- ✓
Role
Why this is correct
Role is a namespaced Kubernetes RBAC resource that defines a set of permissions within a specific namespace, such as allowing a user to get and list pods in the 'default' namespace. It must be paired with a RoleBinding to assign those permissions to a user, group, or service account. Role is the correct answer because it is the namespaced counterpart to ClusterRole and together they serve as the two rule-based RBAC resources.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.