CKS Minimize Microservice Vulnerabilities Practice Question
You run 'kubectl auth can-i create pods --as=system:serviceaccount:default:sa1 -n default' and get 'no'. What does this mean?
⚠ Common exam trap
Candidates may mistake the 'no' response as meaning the service account is missing or invalid, but 'kubectl auth can-i' does not verify existence; it only tests RBAC authorization rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The service account 'sa1' does not have permission to create pods in the default namespace
The command 'kubectl auth can-i create pods --as=system:serviceaccount:default:sa1 -n default' impersonates the service account 'sa1' to check if it has RBAC permissions to create pods in the 'default' namespace. A response of 'no' means that the current RBAC bindings (Role/ClusterRole and RoleBinding/ClusterRoleBinding) do not grant the 'create' verb on 'pods' resources to that service account. This is a direct authorization check against the Kubernetes RBAC system, not an indication of the service account's existence or general capability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The command is invalid because 'system:serviceaccount' is not a valid user
Why it's wrong here
The 'system:serviceaccount' prefix is a valid Kubernetes identifier for service accounts; the fully qualified username is always formatted as system:serviceaccount:<namespace>:<name> (e.g., system:serviceaccount:default:sa1). kubectl auth can-i accepts this format via the --as flag for impersonation, and the command ran successfully, so the syntax is valid. The 'no' result must therefore have a cause other than an invalid user string.
- ✗
The service account 'sa1' does not exist
Why it's wrong here
If service account sa1 were missing from the default namespace, the API server would return a NotFound error when trying to impersonate it, not a plain 'no'. The observed 'no' is a legitimate authorization outcome, meaning the API server found and authenticated the service account identity, evaluated its RBAC rules, and determined that the create pods permission is absent. Thus, a nonexistent service account cannot be the reason for this 'no'.
- ✓
The service account 'sa1' does not have permission to create pods in the default namespace
Why this is correct
The 'no' from kubectl auth can-i is the API server's direct RBAC decision for the exact tuple (verb=create, resource=pods, namespace=default) when impersonating system:serviceaccount:default:sa1. This means no RoleBinding or ClusterRoleBinding grants that service account the create permission on pods in that namespace. It is a precise, scoped denial for that action alone.
- ✗
The service account 'sa1' is not allowed to perform any actions
Why it's wrong here
kubectl auth can-i evaluates only the specific action requested, not the service account's entire authorization matrix. A result of 'no' for create pods in default says nothing about the SA's ability to perform other verbs (like list or delete) or other resource types (like services or configmaps). Inferring that sa1 is forbidden from 'any actions' is therefore an overgeneralization unsupported by this single command.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.