Courseiva
Kubernetes Fundamentals →hardMultiple Choice

KCNA Kubernetes Fundamentals Practice Question

An administrator needs to grant a ServiceAccount in namespace 'dev' permission to list and watch Pods in the same namespace. Which combination of resources is required?

⚠ Common exam trap

The trap here is assuming a ClusterRoleBinding is needed for any RBAC grant, when namespaced permissions should use a Role and RoleBinding to avoid granting cluster-wide access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A Role and a RoleBinding in the 'dev' namespace

To grant a ServiceAccount permission to list and watch Pods in a single namespace, you create a Role in that namespace with the appropriate rules and bind it to the ServiceAccount using a RoleBinding. This follows the principle of least privilege, as the permissions are confined to the 'dev' namespace and do not extend cluster-wide.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A Role and a RoleBinding in the 'dev' namespace

    Why this is correct

    A Role defines permissions within a namespace, and a RoleBinding grants those permissions to a subject such as a ServiceAccount in that namespace. Since the requirement is limited to Pods in 'dev', a Role with verbs list and watch on pods, bound via RoleBinding, provides the necessary access without cluster-wide scope.

  • ✗

    A ClusterRole and a RoleBinding in the 'dev' namespace

    Why it's wrong here

    A ClusterRole with a RoleBinding in 'dev' would grant the permissions defined in the ClusterRole only within the 'dev' namespace. While this is a valid pattern for reusing ClusterRoles, it is not the minimal required combination; a namespaced Role is sufficient and more direct for permissions specific to one namespace. The question asks for the required combination, and Role + RoleBinding is the standard namespaced approach.

  • ✗

    A ClusterRole and a ClusterRoleBinding

    Why it's wrong here

    A ClusterRole and ClusterRoleBinding grant permissions across all namespaces, which exceeds the requirement. While a ClusterRole can be bound with a RoleBinding to limit scope, using a ClusterRoleBinding would allow the ServiceAccount to list Pods in every namespace, violating least privilege. This is over-permissioned for the scenario.

  • ✗

    A Role and a ClusterRoleBinding

    Why it's wrong here

    A ClusterRoleBinding can only reference a ClusterRole, not a namespaced Role. Therefore, this combination is invalid; the API server will reject a ClusterRoleBinding that tries to bind a Role. The correct pairing is Role with RoleBinding, or ClusterRole with RoleBinding for namespaced scope.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.