KCNA Kubernetes Fundamentals Practice Question
A user runs 'kubectl get pods -n default' but receives an error: 'Error from server (Forbidden): pods is forbidden: User cannot list resource pods in API group'. What is the most likely cause?
⚠ Common exam trap
Watch out — candidates often confuse a missing resource (NotFound) with a permissions error (Forbidden), or assume the API server is down when the error is actually a structured RBAC denial. The CNCF exam often tests the distinction between authentication failures (401 Unauthorized) and authorization failures (403 Forbidden).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user lacks RBAC permissions to list pods
The error message 'Error from server (Forbidden): pods is forbidden: User cannot list resource pods in API group' directly indicates that the Kubernetes RBAC (Role-Based Access Control) system has denied the request. The user's current context in their kubeconfig does not have a Role or ClusterRole binding that grants the 'list' verb on 'pods' in the 'v1' API group (core group). This is a standard authorization failure, not a connectivity or resource existence issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The pod does not exist in the namespace
Why it's wrong here
A Forbidden error is returned by the API server's authorisation layer, so the pod's existence is irrelevant; a missing pod would instead yield NotFound. Checking existence is tempting because empty output often means nothing is running, but the error text names authorisation, not absence.
- ✗
The user's kubeconfig file is corrupted
Why it's wrong here
A corrupted kubeconfig typically produces connection or parsing errors before any request reaches the API server, whereas Forbidden proves authentication succeeded and authorisation failed. Blaming the kubeconfig is tempting because it carries user credentials, but the server clearly identified the user and denied the list verb.
- ✓
The user lacks RBAC permissions to list pods
Why this is correct
The Forbidden error names the user and the verb 'list' on pods, which is exactly what RBAC authorises. Authentication succeeded, so the cause is a missing Role or ClusterRole binding granting list on pods in the default namespace.
- ✗
The API server is down
Why it's wrong here
An unavailable API server yields connection refused or timeout errors, not a structured Forbidden response, which only the running server's authorisation layer emits. Suspecting an outage is tempting when commands fail, but the message proves the server processed the request and denied the RBAC check.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.