hardMultiple Choice
CKS Practice Question: You run kube-bench on a node and it reports a…
You run kube-bench on a node and it reports a failure for control plane component etcd. The check says 'Ensure that the --cert-file and --key-file arguments are set as appropriate'. You examine the etcd manifest file and find that the cert-file and key-file are configured with a self-signed certificate. What is the BEST action to remediate this finding?
⚠ Common exam trap
It's easy for candidates to confuse 'self-signed' with 'auto-generated' (option D) or think that adding a CA file (option A) fixes the issue, but the core requirement is that the certificate itself must be signed by a trusted CA, not just that a CA file is present.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the self-signed certificate to one signed by the Kubernetes CA.
Kube-bench expects etcd to use certificates signed by a trusted CA (typically the Kubernetes CA) for secure communication. Self-signed certificates are not trusted by default and can lead to man-in-the-middle attacks or connection failures. Replacing the self-signed certificate with one signed by the Kubernetes CA ensures that the certificate chain is validated, aligning with the CIS Benchmark requirement for etcd.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the --trusted-ca-file flag pointing to the CA certificate.
Why it's wrong here
Adding --trusted-ca-file only tells etcd which CA to use when verifying client certificates; it does not alter the server certificate that etcd presents. The server-side certificate is selected by --cert-file and --key-file, and the benchmark flags the self-signed origin of that certificate. Since kube-apiserver already trusts the Kubernetes CA as part of its cluster PKI, the missing piece is a server certificate signed by that CA, not an extra trust-setting for clients.
- ✗
Remove the --cert-file and --key-file flags to disable TLS.
Why it's wrong here
Removing --cert-file and --key-file disables TLS for etcd's client-server communication, causing it to listen on plain HTTP. This is explicitly forbidden by the CIS Kubernetes Benchmark, which mandates that etcd connections be encrypted and authenticated. Stripping TLS would expose the Kubernetes data store over unsecured connections, making the cluster vulnerable to interception; the proper remediation is to replace the self-signed certificate with one signed by the Kubernetes CA, not to disable encryption.
- ✓
Change the self-signed certificate to one signed by the Kubernetes CA.
Why this is correct
Replacing the self-signed certificate with a certificate signed by the Kubernetes CA satisfies the benchmark because kube-apiserver is already configured to trust certificates issued by that CA. The CIS check verifies that etcd's server certificate is signed by a recognized CA (typically the Kubernetes PKI), rather than being self-signed. This change preserves TLS while establishing a valid certificate chain, so the apiserver can authenticate etcd's identity securely.
- ✗
Set the --auto-tls flag to true to let etcd automatically generate a certificate.
Why it's wrong here
Enabling --auto-tls causes etcd to automatically generate self-signed certificates, which are not signed by the Kubernetes CA and therefore are not trusted by kube-apiserver without explicitly adding that CA to the apiserver's trust store. The CIS benchmark specifically requires a CA-signed certificate rather than any self-signed one, regardless of whether it is generated manually or via auto-tls. Auto-tls is documented mainly for development and testing; using it in production would leave etcd's identity unverified and fail the benchmark's security requirement.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.