CKS System Hardening Practice Question
You are managing a Kubernetes cluster that hosts multiple microservices. The cluster uses Kubernetes v1.25. Recently, a security audit identified that containers are running with the default seccomp profile (unconfined). The security team has requested that all containers use a seccomp profile that blocks unnecessary syscalls. You need to implement this cluster-wide without breaking existing applications. The audit also found that the kubelet's anonymous authentication is enabled, which should be disabled. Additionally, you need to ensure that the kubelet's NodeRestriction admission controller is enabled to limit what nodes can do. Which of the following is the most appropriate sequence of actions?
⚠ Common exam trap
The trap here is that candidates rush to apply the restrictive seccomp profile immediately (options A, B, C) without considering the need for a gradual rollout via logging mode to avoid breaking existing applications, which is a key CKS focus on safe system hardening.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
First, configure the kubelet to use a seccomp profile that logs violations (e.g., 'runtime/default' with log), then after verifying no breakage, switch to 'runtime/default'. Then disable anonymous authentication and enable NodeRestriction admission controller
It follows the principle of least disruption: first, it applies the 'runtime/default' seccomp profile in logging mode to detect any blocked syscalls without breaking applications. After verifying no breakage, it switches to enforcing mode. Then, it disables anonymous authentication and enables the NodeRestriction admission controller, both of which are non-disruptive configuration changes. This sequence minimizes risk to existing workloads while meeting all audit requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable anonymous authentication immediately, then enable NodeRestriction, and finally apply the restrictive seccomp profile
Why it's wrong here
Disabling anonymous authentication before enabling NodeRestriction and before testing seccomp reverses the safe rollout order. Kubelets and monitoring components may initially rely on permissive authentication, so cutting it off immediately can cause node authorization failures and API outages, leaving the cluster unavailable before the NodeRestriction admission controller is in place to constrain kubelet requests. Also, applying the restrictive seccomp profile last means workloads remain unprotected for the entire window, increasing exposure while the riskiest change is still untested.
- ✗
Apply the 'runtime/default' seccomp profile cluster-wide immediately, then disable anonymous auth, and finally enable NodeRestriction
Why it's wrong here
Applying 'runtime/default' cluster-wide immediately, without a logging phase, turns seccomp enforcement into a blind rollout that can crash every workload relying on a blocked syscall. Because the profile is applied to all nodes and pods at once, the blast radius is enormous, and there is no chance to observe violations in an audit log before deciding to enforce. The correct sequence first lets you detect incompatible syscalls without blocking them, preventing widespread application failures while preserving security hardening.
- ✗
Enable NodeRestriction first, then apply a restrictive seccomp profile, and last disable anonymous authentication
Why it's wrong here
Enabling NodeRestriction first is a reasonable authorization hardening step, but the sequence still fails because a restrictive seccomp profile is forced into enforcement before any violation logging or compatibility verification. NodeRestriction only limits kubelet API permissions; it cannot prevent an incompatible seccomp policy from denying syscalls to existing workloads, which causes subtle runtime crashes. Postponing the disablement of anonymous authentication to the end also leaves a serious unauthenticated access hole open during the entire migration, so the cluster never reaches a fully hardened state until the very last step, with no opportunity to safely abort after seccomp changes.
- ✓
First, configure the kubelet to use a seccomp profile that logs violations (e.g., 'runtime/default' with log), then after verifying no breakage, switch to 'runtime/default'. Then disable anonymous authentication and enable NodeRestriction admission controller
Why this is correct
This order works because it first configures the kubelet to use a seccomp profile that logs violations, such as a Localhost profile that maps default-blocked syscalls to SCMP_ACT_LOG instead of SCMP_ACT_ERRNO. After observing logs for a period and confirming that no application-required syscall is being denied, you can switch to enforcing 'runtime/default' with low risk. Then, disabling anonymous authentication closes unauthenticated access to the kubelet/API, and enabling NodeRestriction constrains what a compromised kubelet can change, completing the hardening. This phased approach, validate-then-enforce, prevents downtime and gives you evidence for every security decision.
Go deeper
Related to this question
Learn chapter
Cluster Hardening: Node and Container Security
Key term
Node Restriction
A Kubernetes admission controller that limits what a kubelet can modify on its own node to prevent privilege escalation and unauthorized access.
Key term
Seccomp Profiles
Seccomp profiles are security filters that restrict which system calls a containerized application can make to the Linux kernel, reducing the attack surface.
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.