mediumMultiple Choice
CKS Practice Question: You run 'kube-bench' and see a failure: '1.2.7…
You run 'kube-bench' and see a failure: '1.2.7 Ensure that the --kubelet-client-certificate and --kubelet-client-key arguments are set as appropriate'. What is the impact of this misconfiguration?
⚠ Common exam trap
Many candidates assume the API server will simply fail or reject requests when missing client certificates, but in reality, Kubernetes defaults to allowing anonymous authentication unless explicitly disabled, so the impact is a security bypass rather than a denial of service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The apiserver will use anonymous authentication when connecting to kubelets
When the API server lacks a properly configured client certificate and key for kubelet communication, it falls back to anonymous authentication when making requests to kubelets. This means the kubelet cannot verify the API server's identity, allowing any unauthenticated request to be processed, which violates the principle of mutual TLS (mTLS) and weakens cluster security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The apiserver will use the kubelet's own certificate
Why it's wrong here
The kubelet's certificate is a serving certificate presented by the kubelet when it acts as an HTTPS server; the apiserver does not have the private key needed to use it as a client credential. Even if the public certificate were relayed, the kubelet's --client-ca-file would not trust it as a client cert, and its Extended Key Usage normally includes serverAuth rather than clientAuth. The apiserver must present its own distinct client certificate and key via --kubelet-client-certificate/--kubelet-client-key, so this outcome is impossible.
- ✗
The kubelet will refuse to register with the cluster
Why it's wrong here
Node registration is the kubelet's initial call to the Kubernetes API with the kubelet's own credentials (usually a bootstrap token or a client cert), not a connection from the apiserver to the kubelet. The CIS failure about setting the apiserver's --kubelet-client-certificate and --kubelet-client-key affects the reverse direction: apiserver-to-kubelet calls for logs, exec, and metrics. Therefore, a missing apiserver client cert has no effect on whether the kubelet can register its Node object with the cluster.
- ✓
The apiserver will use anonymous authentication when connecting to kubelets
Why this is correct
When the apiserver is not configured with a client certificate and key, it makes the HTTPS request to the kubelet without presenting any client certificate. The kubelet treats this as an unauthenticated connection; if --anonymous-auth is true (the default), it maps the caller to the user system:anonymous and may serve the request if anonymous access is permitted by its authorization policy. This is exactly the risk the CIS check addresses: a kubelet could authorize anonymous requests for pod logs or exec, so the apiserver must have a dedicated, trusted client certificate.
- ✗
The apiserver will reject all requests to kubelets
Why it's wrong here
Requests are not guaranteed to be rejected; whether the kubelet refuses them depends on its --anonymous-auth setting and its authorization mode. If anonymous auth is enabled and the kubelet's authorizer grants the system:anonymous user any permissions, the apiserver's request can succeed. If anonymous auth is disabled, the kubelet may return 401 Unauthorized, but that is the kubelet refusing the request based on its own configuration, not the apiserver rejecting all on its own.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.