โ† All KCNA Flashcard Decks

Security and RBAC Flashcards

7 cards from real KCNA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security and RBAC flashcards as text
  1. Which Kubernetes component is responsible for authenticating requests to the API server?

    Answer: kube-apiserver

    The kube-apiserver handles authentication of all API requests using configured authenticator plugins (certificates, tokens, OIDC, etc.).

  2. What is the Kubernetes API group for RBAC resources like Role and RoleBinding?

    Answer: rbac.authorization.k8s.io

    RBAC resources (Role, ClusterRole, RoleBinding, ClusterRoleBinding) belong to the `rbac.authorization.k8s.io` API group.

  3. What happens when `allowPrivilegeEscalation: false` is set in a container's securityContext?

    Answer: The container cannot gain more privileges than its parent process

    Setting `allowPrivilegeEscalation: false` prevents a process from gaining more privileges than its parent, blocking setuid and sudo-like escalations.

  4. Which Pod Security Standard level is recommended for most workloads requiring some relaxation but still security-conscious?

    Answer: baseline

    The 'baseline' level prevents known privilege escalations while being minimally restrictive, making it suitable for most general workloads.

  5. In Kubernetes, what are 'non-resource URLs' in RBAC context?

    Answer: API endpoints not tied to a Kubernetes resource object, such as /healthz

    Non-resource URLs are API server endpoints like /healthz, /metrics, and /version that don't correspond to a Kubernetes API resource object.

  6. What is the recommended way to provide a Pod with access to the Kubernetes API in modern Kubernetes (1.24+)?

    Answer: Use a ServiceAccount with appropriate RBAC and projected token volumes

    The recommended approach is to use a dedicated ServiceAccount with minimal RBAC permissions and projected ServiceAccount tokens for short-lived, audience-bound credentials.

  7. Which kubectl command lists all ClusterRoleBindings in a cluster?

    Answer: kubectl get clusterrolebindings

    The command `kubectl get clusterrolebindings` lists all ClusterRoleBinding objects, which are cluster-scoped and not namespaced.