Courseiva
KCSA
Kubernetes Security FundamentalsmediumMultiple ChoiceObjective-mapped

KCSA Kubernetes Security Fundamentals Practice Question

Your team is storing sensitive database credentials in Kubernetes Secrets. A security review reveals that base64 encoding does not provide encryption at rest. What mechanism should you enable to ensure Secrets are encrypted when stored in etcd?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure an EncryptionConfiguration file and reference it via the '--encryption-provider-config' flag on the kube-apiserver.

Enabling EncryptionConfiguration with providers like aescbc or kms ensures that API server encrypts secret data before writing it to etcd.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Apply a MutatingWebhookConfiguration to automatically hash passwords using bcrypt.

    Why it's wrong here

    Mutating webhooks can modify manifests, but standard Kubernetes Secrets expect base64 and depend on storage-level encryption.

  • Enable TLS encryption for all intra-cluster communication using kubeadm configuration.

    Why it's wrong here

    TLS protects data in transit over the network, not data at rest in the etcd database.

  • Configure an EncryptionConfiguration file and reference it via the '--encryption-provider-config' flag on the kube-apiserver.

    Why this is correct

    This is the native Kubernetes mechanism for encrypting Secret resources at rest in etcd.

  • Set the secret type to 'kubernetes.io/encrypted-secret'.

    Why it's wrong here

    This is not a valid built-in Kubernetes Secret type.

About these practice questions

One of 320 original KCSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official CNCF / Linux Foundation exam blueprint

This KCSA practice question is part of Courseiva's free CNCF / Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCSA exam.