hardMultiple Choice
CKS Securing etcd Practice Question
You are securing etcd. Which of the following is required to enable TLS client authentication for etcd?
⚠ Common exam trap
Many exam-takers confuse `--peer-client-cert-auth` (for inter-node communication) with `--client-cert-auth` (for client-to-server communication), leading them to select option B instead of D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set --client-cert-auth to true and provide --trusted-ca-file
Etcd requires `--client-cert-auth=true` to enforce TLS client certificate authentication for incoming client requests, and `--trusted-ca-file` must be provided to specify the CA certificate used to validate client certificates. Without both, client certificate authentication is not enabled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set --auto-tls to true
Why it's wrong here
Setting --auto-tls to true is incorrect because this flag only controls automatic self-signed certificate generation for peer-to-peer communication between etcd members. It does not authenticate or even request certificates from client connections; in fact, auto-tls intentionally bypasses certificate verification for peers by using self-signed certificates. Client authentication requires explicitly enabling --client-cert-auth, which auto-tls does not do.
- ✗
Set --peer-client-cert-auth to true
Why it's wrong here
The --peer-client-cert-auth flag governs authentication between etcd peers in the cluster, not between clients and the etcd server. It forces peer nodes to present certificates when communicating with each other, but client requests over the client URL are unaffected. To authenticate clients, you must set --client-cert-auth on the client-facing endpoint, which is a separate and independent setting.
- ✗
Use --cert-file and --key-file only
Why it's wrong here
Supplying only --cert-file and --key-file enables TLS server-side encryption, meaning the server presents its certificate to clients and encrypts traffic, but it never asks the client for a certificate. Without --client-cert-auth=true, the server cannot verify or enforce any client identity, leaving the endpoint open to any client that can reach it. Therefore, these two flags are insufficient for client authentication.
- ✓
Set --client-cert-auth to true and provide --trusted-ca-file
Why this is correct
The correct configuration is to set --client-cert-auth=true, which forces etcd to require a certificate from every client, and provide --trusted-ca-file to tell etcd which CA to use when verifying those client certificates. Together these flags implement mutual TLS: clients verify the server via the server's certificate, and the server verifies clients via their CA-signed certs. This is the standard way to authenticate and authorize access to etcd in a hardened Kubernetes control plane.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.