hardMultiple Choice
CKS Tasked with securing the kubelet Practice Question
You are tasked with securing the kubelet. Which flag must be set on the kubelet to enable the NodeRestriction admission plugin?
⚠ Common exam trap
A common mix-up: candidates confuse the kubelet's role with the kube-apiserver's role, assuming admission plugins are configured on the kubelet because the NodeRestriction plugin directly affects kubelet behavior, but in reality admission plugins are always server-side components on the kube-apiserver.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--enable-admission-plugins=NodeRestriction on the kube-apiserver
The NodeRestriction admission plugin is an admission controller that runs on the kube-apiserver, not on the kubelet. It limits the Node and Pod objects a kubelet can modify, enforcing that nodes can only modify their own node object and pods bound to them. The flag `--enable-admission-plugins=NodeRestriction` on the kube-apiserver activates this plugin, which is a key security control for hardening the cluster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
--admission-control=NodeRestriction on the kubelet
Why it's wrong here
The --admission-control flag is deprecated and was historically used on the kube-apiserver, not the kubelet. The kubelet has no admission control chain and cannot enforce NodeRestriction. Admission controllers are components of the API server that intercept requests before they are persisted. Therefore, specifying this flag on the kubelet is both syntactically and architecturally incorrect.
- ✗
--enable-admission-plugins=NodeRestriction on the kubelet
Why it's wrong here
The --enable-admission-plugins flag exists only on the kube-apiserver, where it lists the admission controllers that should be activated. The kubelet is a node-level agent that does not process API admission webhooks or abstract authorization decisions. NodeRestriction is an API server admission plugin that must run in the kube-apiserver's request pipeline. Passing it to the kubelet would either be ignored or cause a startup failure.
- ✗
--node-restriction=true on the kubelet
Why it's wrong here
There is no --node-restriction=true flag in any Kubernetes component. NodeRestriction is not a boolean toggle; it is an admission controller that must be included in the --enable-admission-plugins list on the kube-apiserver. Even if such a flag existed on the kubelet, it would not activate the API server-side admission logic. This option confuses a feature with a simple configuration switch and mistakenly targets the wrong component.
- ✓
--enable-admission-plugins=NodeRestriction on the kube-apiserver
Why this is correct
The correct approach is to enable the NodeRestriction admission controller on the kube-apiserver using --enable-admission-plugins=NodeRestriction. This plugin is part of the API server's admission chain and works together with the Node authorizer to restrict kubelet requests. For example, it prevents a compromised kubelet from modifying any Node object other than its own or from writing to Pod objects. This flag must be placed in the kube-apiserver's startup configuration, not on the kubelet.
Go deeper
Related to this question
Learn chapter
Cluster Hardening: Resource Quotas and Limit Ranges
Key term
OPA Gatekeeper
OPA Gatekeeper is a Kubernetes admission controller that enforces custom security and compliance policies on resources before they are created or updated in a cluster.
Key term
Node Restriction
A Kubernetes admission controller that limits what a kubelet can modify on its own node to prevent privilege escalation and unauthorized access.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.