Courseiva
mediumMultiple Select

CKS Practice Question: Which TWO resources can be used to implement RBAC…

Which TWO resources can be used to implement RBAC in Kubernetes?

⚠ Common exam trap

CNCF often tests the distinction between RBAC authorization resources (Role/ClusterRole) and other Kubernetes objects that deal with security but serve different purposes, such as NetworkPolicy (network segmentation) or PodSecurityPolicy (pod security constraints), leading candidates to confuse authorization with other security controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ClusterRole

A is correct because ClusterRole is a Kubernetes RBAC resource that defines a set of permissions (rules) that are not namespaced, allowing cluster-wide access. RBAC in Kubernetes uses Role and ClusterRole objects to specify allowed verbs (e.g., get, list, create) on resources (e.g., pods, secrets), and they are bound to subjects via RoleBinding or ClusterRoleBinding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ClusterRole

    Why this is correct

    ClusterRole is a Kubernetes RBAC object that defines permissions, such as verbs (get, list, create) on resources (pods, deployments), but unlike Role it is cluster-scoped. It can grant cluster-wide access when bound via a ClusterRoleBinding, or it can be reused in a single namespace by binding it with a RoleBinding, whose effective permissions are scoped to that namespace. ClusterRole is the correct answer because it is one of the two primary RBAC rule resources, alongside Role.

  • ✗

    NetworkPolicy

    Why it's wrong here

    NetworkPolicy is a namespaced Kubernetes resource that controls traffic flow between pods, namespaces, and external endpoints at the network layer (L3/L4). It is completely unrelated to authorization of API requests; RBAC restricts what a user or service account can do with the Kubernetes API, not which pods can communicate with each other. Therefore, NetworkPolicy cannot implement RBAC.

  • ✗

    PodSecurityPolicy

    Why it's wrong here

    PodSecurityPolicy was an admission controller resource that enforced security constraints on pod specifications, such as privileged mode, host namespaces, and allowed capabilities. It never defined user permissions or API access rules, so it was not a component of RBAC. Moreover, PodSecurityPolicy was deprecated in Kubernetes 1.21 and removed in 1.25, making it even less relevant to current RBAC implementations.

  • ✗

    ServiceAccount

    Why it's wrong here

    ServiceAccount is an identity object used by pods to authenticate to the Kubernetes API server. While RBAC involves granting permissions to service accounts through Roles or ClusterRoles and their bindings, the ServiceAccount resource itself contains no permission rules—it merely represents a non-human principal. Thus, a ServiceAccount is a subject for authorization, not an RBAC resource that defines permissions.

  • ✓

    Role

    Why this is correct

    Role is a namespaced Kubernetes RBAC resource that defines a set of permissions within a specific namespace, such as allowing a user to get and list pods in the 'default' namespace. It must be paired with a RoleBinding to assign those permissions to a user, group, or service account. Role is the correct answer because it is the namespaced counterpart to ClusterRole and together they serve as the two rule-based RBAC resources.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.