hardMultiple Choice
CKS Run kube-bench on a control plane node Practice Question
You need to run kube-bench on a control plane node. Which command should you use?
⚠ Common exam trap
Many exam-takers assume the target name matches the modern Kubernetes terminology 'controlplane', but `kube-bench` still uses the legacy term 'master' for backward compatibility with the CIS Benchmark.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kube-bench run --targets=master
`kube-bench` uses the `--targets` flag to specify which CIS benchmark targets to scan, and for control plane nodes, the correct target is `master` (not `controlplane`). This is because the CIS Kubernetes Benchmark historically refers to the control plane node as the 'master' node, and `kube-bench` follows that naming convention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kube-bench run --targets=controlplane
Why it's wrong here
kube-bench does not recognize the target name 'controlplane'. The CLI rejects it, so no checks execute and the command exits with an invalid target error. The CIS Kubernetes Benchmark groups all control plane components under the exact target 'master', so you must use that supported name to trigger any control plane audit.
- ✓
kube-bench run --targets=master
Why this is correct
This is the correct invocation because 'master' is the kube-bench target that maps to the control plane section of the CIS Kubernetes Benchmark. Running with --targets=master audits kube-apiserver, kube-controller-manager, kube-scheduler, and etcd bundles on the control plane node. It ensures comprehensive coverage of control plane checks rather than a partial or empty run.
- ✗
kube-bench run --targets=node
Why it's wrong here
The 'node' target runs only benchmarks for worker-node components such as kubelet and kube-proxy, which are not the focus of a control plane audit. On a control plane node, this skips the API server, controller-manager, and scheduler checks, leaving critical security settings unexamined. Even though a control plane node may run kubelet, the node target does not substitute for the master target.
- ✗
kube-bench run --targets=etcd
Why it's wrong here
The 'etcd' target restricts kube-bench to the etcd-only checks in the CIS benchmark, but the control plane includes more than etcd. This command would not audit kube-apiserver, kube-scheduler, or kube-controller-manager, so a major portion of the control plane remains unchecked. Since the prompt asks for control plane checks, limiting the scan to etcd is insufficient and incorrect.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.