Security and RBAC Flashcards
7 cards from real KCNA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security and RBAC flashcards as text
Which Kubernetes component is responsible for authenticating requests to the API server?
Answer: kube-apiserver
The kube-apiserver handles authentication of all API requests using configured authenticator plugins (certificates, tokens, OIDC, etc.).
What is the Kubernetes API group for RBAC resources like Role and RoleBinding?
Answer: rbac.authorization.k8s.io
RBAC resources (Role, ClusterRole, RoleBinding, ClusterRoleBinding) belong to the `rbac.authorization.k8s.io` API group.
What happens when `allowPrivilegeEscalation: false` is set in a container's securityContext?
Answer: The container cannot gain more privileges than its parent process
Setting `allowPrivilegeEscalation: false` prevents a process from gaining more privileges than its parent, blocking setuid and sudo-like escalations.
Which Pod Security Standard level is recommended for most workloads requiring some relaxation but still security-conscious?
Answer: baseline
The 'baseline' level prevents known privilege escalations while being minimally restrictive, making it suitable for most general workloads.
In Kubernetes, what are 'non-resource URLs' in RBAC context?
Answer: API endpoints not tied to a Kubernetes resource object, such as /healthz
Non-resource URLs are API server endpoints like /healthz, /metrics, and /version that don't correspond to a Kubernetes API resource object.
What is the recommended way to provide a Pod with access to the Kubernetes API in modern Kubernetes (1.24+)?
Answer: Use a ServiceAccount with appropriate RBAC and projected token volumes
The recommended approach is to use a dedicated ServiceAccount with minimal RBAC permissions and projected ServiceAccount tokens for short-lived, audience-bound credentials.
Which kubectl command lists all ClusterRoleBindings in a cluster?
Answer: kubectl get clusterrolebindings
The command `kubectl get clusterrolebindings` lists all ClusterRoleBinding objects, which are cluster-scoped and not namespaced.