Courseiva
hardMultiple Choice

CKS Practice Question: Create a ClusterRole that allows listing secrets,…

You need to create a ClusterRole that allows listing secrets, but only in namespaces that have a specific label 'security-level=high'. Which approach should you use?

⚠ Common exam trap

Many exam-takers confuse ClusterRoleBindings with RoleBindings, assuming a ClusterRole must always be bound with a ClusterRoleBinding, or they mistakenly think that a ClusterRole can include a namespace selector to limit its scope, which is not supported in Kubernetes RBAC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a ClusterRole and bind it with RoleBindings in each labeled namespace

ClusterRoleBindings grant permissions cluster-wide, but RoleBindings can bind a ClusterRole to subjects within specific namespaces. By creating a ClusterRole with the necessary rules (e.g., 'list secrets') and then creating RoleBindings only in namespaces that have the label 'security-level=high', you effectively restrict the permission to those namespaces. This approach leverages the fact that a ClusterRole can be used with RoleBindings to scope permissions to individual namespaces.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a ClusterRole and bind it with RoleBindings in each labeled namespace

    Why this is correct

    A ClusterRole defines a set of permissions that are not tied to any namespace, but when you reference it in a RoleBinding, the binding's namespace becomes the effective scope. This lets you reuse one ClusterRole across selected namespaces by creating a RoleBinding in each namespace that has the target label. The permissions apply only in those namespaces, not cluster-wide, which satisfies the requirement to list secrets only in labeled namespaces.

  • ✗

    Create a Role in each namespace, then aggregate them into a ClusterRole

    Why it's wrong here

    ClusterRole aggregation (aggregationRule) works by selecting other ClusterRoles through label selectors, and it combines their rules into the aggregated ClusterRole. You cannot aggregate namespaced Roles into a ClusterRole because aggregation only looks at ClusterRole objects, and Roles do not carry the labels that the aggregationRule selector would match. Additionally, Roles already restrict permissions to a single namespace, so aggregating them would not create a cluster-scoped permission set.

  • ✗

    Create a ClusterRole and bind it with a ClusterRoleBinding; add a namespace condition in the role

    Why it's wrong here

    A ClusterRoleBinding grants a ClusterRole's permissions across all namespaces in the cluster, with no built-in way to scope the binding to a subset of namespaces. RBAC rules (the rules field in a Role or ClusterRole) only specify API groups, resources, and verbs; they cannot include a namespace condition or selector to filter where the permission applies. The only valid pattern to limit a ClusterRole's effect to specific namespaces is to use RoleBindings, not ClusterRoleBindings.

  • ✗

    Create a ClusterRole with a namespaceSelector: matchLabels: security-level: high

    Why it's wrong here

    A ClusterRole does not have a namespaceSelector field in its specification. In Kubernetes RBAC, the namespaceSelector field appears in Pod nodeSelectors and NetworkPolicy podSelectors, but never in role definitions or bindings. The only way to tie a ClusterRole to a specific namespace is to bind it via a RoleBinding in that namespace, which inherently scopes it; there is no declarative selector that does this at the ClusterRole level.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.