Courseiva
hardMultiple Choice

CKS Securing etcd Practice Question

You are securing etcd. Which of the following is required to enable TLS client authentication for etcd?

⚠ Common exam trap

Many exam-takers confuse `--peer-client-cert-auth` (for inter-node communication) with `--client-cert-auth` (for client-to-server communication), leading them to select option B instead of D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set --client-cert-auth to true and provide --trusted-ca-file

Etcd requires `--client-cert-auth=true` to enforce TLS client certificate authentication for incoming client requests, and `--trusted-ca-file` must be provided to specify the CA certificate used to validate client certificates. Without both, client certificate authentication is not enabled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set --auto-tls to true

    Why it's wrong here

    Setting --auto-tls to true is incorrect because this flag only controls automatic self-signed certificate generation for peer-to-peer communication between etcd members. It does not authenticate or even request certificates from client connections; in fact, auto-tls intentionally bypasses certificate verification for peers by using self-signed certificates. Client authentication requires explicitly enabling --client-cert-auth, which auto-tls does not do.

  • ✗

    Set --peer-client-cert-auth to true

    Why it's wrong here

    The --peer-client-cert-auth flag governs authentication between etcd peers in the cluster, not between clients and the etcd server. It forces peer nodes to present certificates when communicating with each other, but client requests over the client URL are unaffected. To authenticate clients, you must set --client-cert-auth on the client-facing endpoint, which is a separate and independent setting.

  • ✗

    Use --cert-file and --key-file only

    Why it's wrong here

    Supplying only --cert-file and --key-file enables TLS server-side encryption, meaning the server presents its certificate to clients and encrypts traffic, but it never asks the client for a certificate. Without --client-cert-auth=true, the server cannot verify or enforce any client identity, leaving the endpoint open to any client that can reach it. Therefore, these two flags are insufficient for client authentication.

  • ✓

    Set --client-cert-auth to true and provide --trusted-ca-file

    Why this is correct

    The correct configuration is to set --client-cert-auth=true, which forces etcd to require a certificate from every client, and provide --trusted-ca-file to tell etcd which CA to use when verifying those client certificates. Together these flags implement mutual TLS: clients verify the server via the server's certificate, and the server verifies clients via their CA-signed certs. This is the standard way to authenticate and authorize access to etcd in a hardened Kubernetes control plane.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.