Courseiva
Kubernetes Fundamentals →mediumMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

A cluster administrator needs to grant a user permission to view Pods in the 'staging' namespace but not in any other namespace. Which combination of Kubernetes objects should be created?

⚠ Common exam trap

The trap here is thinking that a ClusterRole and RoleBinding is the only way to grant namespaced access, but a simple Role and RoleBinding is sufficient and more precise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A Role and a RoleBinding in the 'staging' namespace

To grant namespace-scoped permissions, the standard approach is to create a Role that defines the allowed verbs on Pods and a RoleBinding that binds that Role to the user within the 'staging' namespace. This ensures the user can view Pods only in that namespace, following the principle of least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A Role and a RoleBinding in the 'staging' namespace

    Why this is correct

    A Role defines permissions within a specific namespace, and a RoleBinding grants those permissions to a user within that same namespace. Creating both in the 'staging' namespace limits the user's ability to view Pods to that namespace only, satisfying the requirement.

  • ✗

    A ClusterRole and a RoleBinding in the 'staging' namespace

    Why it's wrong here

    A ClusterRole can be bound with a RoleBinding to grant permissions only within a specific namespace, which would work for this scenario. However, the question asks for the combination that should be created; using a ClusterRole is unnecessary when a Role suffices. The most direct and least-privilege approach is a Role and RoleBinding.

  • ✗

    A ClusterRole and a ClusterRoleBinding

    Why it's wrong here

    A ClusterRole with a ClusterRoleBinding grants permissions across the entire cluster, not limited to a single namespace. This would allow the user to view Pods in all namespaces, which violates the requirement to restrict access to only the 'staging' namespace.

  • ✗

    A Role and a ClusterRoleBinding

    Why it's wrong here

    A Role is namespace-scoped, but a ClusterRoleBinding grants permissions cluster-wide. Binding a namespaced Role with a ClusterRoleBinding is not valid for restricting to a single namespace; it would either fail or grant broader access. This combination does not correctly limit the user to the 'staging' namespace.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.