mediumMultiple Choice
CKS Practice Question: Ensure that kubelet does not allow anonymous…
You want to ensure that kubelet does not allow anonymous requests. Which flag must be set on the kubelet?
⚠ Common exam trap
CNCF often tests the exact flag name `--anonymous-auth` versus similar-sounding alternatives like `--authentication-anonymous` or `--allow-anonymous`, exploiting the fact that candidates may guess based on generic naming conventions rather than knowing the precise kubelet flag syntax.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--anonymous-auth=false
The kubelet's `--anonymous-auth` flag controls whether anonymous requests to the kubelet API are permitted. Setting `--anonymous-auth=false` explicitly denies all anonymous requests, ensuring that only authenticated users can interact with the kubelet. This is a critical hardening step to prevent unauthenticated access to node-level operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
--anonymous-auth=false
Why this is correct
The `--anonymous-auth=false` flag is the correct kubelet server flag to disable anonymous requests. When set to false, the kubelet's secure port (10250) rejects any request that does not present valid client credentials, returning HTTP 401. This is a core kubelet hardening setting that ensures only authenticated and authorized clients can interact with the kubelet API.
- ✗
--authentication-anonymous=false
Why it's wrong here
`--authentication-anonymous=false` is not a valid kubelet flag. The kubelet uses the simplified `--anonymous-auth` boolean for enabling or disabling anonymous access; there is no separate `--authentication-anonymous` option in any Kubernetes component. Attempting to pass this flag to the kubelet would cause a startup error due to an unrecognized flag, so it cannot secure the kubelet.
- ✗
--allow-anonymous=false
Why it's wrong here
`--allow-anonymous=false` is a fabricated option that does not exist in the kubelet or in any other Kubernetes component. Anonymous authentication is controlled exclusively by `--anonymous-auth` (and for some components, `--anonymous-auth` on the API server), not by any flag named `--allow-anonymous`. Using this non-existent flag would have no effect and would likely prevent the kubelet from starting due to an unknown flag.
- ✗
--read-only-port=0
Why it's wrong here
Setting `--read-only-port=0` disables the kubelet's read-only port (10255), which historically served unauthenticated read-only endpoints. However, this does not affect anonymous requests on the secure port (10250), where the kubelet serves the main API. If `--anonymous-auth` remains true, anonymous requests can still reach the secure endpoint, so this flag alone is insufficient to enforce authentication.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which kubelet flag should be set to ensure the kubelet does not allow anonymous requests?
easy- A.--authentication-token-webhook=true
- B.--read-only-port=0
- ✓ C.--anonymous-auth=false
- D.--protect-kernel-defaults=true
Why C: Setting `--anonymous-auth=false` explicitly disables anonymous requests to the kubelet. By default, anonymous authentication is enabled, which allows unauthenticated users to access the kubelet API. Disabling this flag ensures that only authenticated requests are processed, aligning with the principle of least privilege and hardening the cluster.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.