Courseiva
mediumMultiple Choice

CKS Practice Question: You have a requirement to encrypt secrets at rest…

You have a requirement to encrypt secrets at rest in etcd. Which resource and apiVersion should be used?

⚠ Common exam trap

CNCF often tests the exact resource name and API group, and the trap here is that candidates confuse `EncryptionConfiguration` with made-up names like `EtcdEncryption` or `SecretEncryption`, or incorrectly assume it belongs to the core `v1` API group instead of `apiserver.config.k8s.io`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EncryptionConfiguration with apiVersion apiserver.config.k8s.io/v1

The Kubernetes API server uses an `EncryptionConfiguration` resource with `apiVersion apiserver.config.k8s.io/v1` to define how secrets and other resources are encrypted at rest in etcd. This resource specifies providers (e.g., `aescbc`, `secretbox`) and keys, and is loaded via the `--encryption-provider-config` flag on the API server. The `v1` version is the stable, production-ready API version for this configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    EtcdEncryption with apiVersion apiserver.config.k8s.io/v1beta1

    Why it's wrong here

    No EtcdEncryption resource exists in Kubernetes; encryption at rest is declared in the EncryptionConfiguration file passed to kube-apiserver via --encryption-provider-config. The apiserver.config.k8s.io group is real, which makes the fabricated kind look credible, but no such API object is served.

  • ✗

    EncryptionConfig with apiVersion v1

    Why it's wrong here

    EncryptionConfig is not a served Kubernetes API resource; the correct artefact is the EncryptionConfiguration file supplied to kube-apiserver through --encryption-provider-config, listing providers such as aescbc. The v1 apiVersion is invalid for it, so this cannot be applied as a resource.

  • ✗

    SecretEncryption with apiVersion v1

    Why it's wrong here

    Kubernetes has no SecretEncryption resource; encryption is configured through the EncryptionConfiguration file referenced by the kube-apiserver's --encryption-provider-config flag. The name is invented, so the API server would reject it. It tempts candidates who assume a dedicated Secret-scoped object exists for at-rest encryption.

  • ✓

    EncryptionConfiguration with apiVersion apiserver.config.k8s.io/v1

    Why this is correct

    EncryptionConfiguration is the Kubernetes resource that defines encryption at rest for etcd, and apiserver.config.k8s.io/v1 is its correct apiVersion. This satisfies the requirement to encrypt secrets at rest by configuring the kube-apiserver's encryption provider, distinct from Secret or EncryptionKey resources.

Go deeper

Related to this question

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.