Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

You need to enforce that no pod runs with privileged containers or runs as root. Which tool can define policies that block such pods at admission time?

⚠ Common exam trap

A common mistake is confusing runtime enforcement (e.g., AppArmor, seccomp) with admission-time enforcement (e.g., OPA Gatekeeper, PodSecurity Admission). Candidates often choose NetworkPolicy because it 'blocks' something, but it blocks network traffic, not pod creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

OPA Gatekeeper

OPA Gatekeeper is a Kubernetes admission controller that enforces custom policies defined via the Constraint Framework (CF). It can reject pods that request privileged containers or run as root by evaluating constraints against the PodSecurityPolicy-like rules expressed in Rego, blocking them before they are persisted in etcd.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Kubernetes Secret

    Why it's wrong here

    A Kubernetes Secret is an API object designed to store sensitive data such as passwords, tokens, or cryptographic keys, typically base64-encoded but not encrypted at rest by default. It has no admission control or policy enforcement capabilities; it simply provides data to pods via volumes or environment variables. Creating or managing Secrets cannot prevent pods from running privileged containers because Secrets do not inspect or control pod security contexts. Therefore, Secrets are entirely disconnected from enforcing pod privilege policies.

  • ✗

    PodDisruptionBudget

    Why it's wrong here

    A PodDisruptionBudget (PDB) specifies the minimum number of pods in a ReplicaSet, Deployment, or StatefulSet that must remain available during voluntary disruptions such as node drains, cluster upgrades, or autoscaling decisions. It is a scheduling and availability control, not a security control, and it operates at the controller level without examining pod security fields. PDBs do not intercept pod creation requests and cannot reject or mutate a pod that requests privileged: true. Thus, a PDB would be ineffective for ensuring that no pod runs with privileged containers.

  • ✓

    OPA Gatekeeper

    Why this is correct

    OPA Gatekeeper is a validating admission webhook based on Open Policy Agent that evaluates every pod creation request against customizable ConstraintTemplates and Constraints defined by cluster administrators. It can inspect any field in the pod specification, including securityContext.privileged, and reject or mutate requests that violate defined policies. For example, a constraint can deny any pod with privileged: true, effectively enforcing the 'no privileged containers' rule. Because Gatekeeper intercepts API requests during admission, it is the correct and powerful mechanism to enforce such pod security policies.

  • ✗

    NetworkPolicy

    Why it's wrong here

    A NetworkPolicy is a Kubernetes resource that controls which pods can communicate with each other and with external endpoints, using selectors, ports, and ingress/egress rules at the network layer. It operates only on traffic flow after pods are running and has no ability to inspect or modify pod specs at creation time. NetworkPolicy cannot prevent a pod from being created with privileged: true; it merely limits its network connectivity. Therefore, NetworkPolicy is unrelated to enforcing pod security constraints like privilege.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.