Security and RBAC Flashcards
7 cards from real KCNA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security and RBAC flashcards as text
What is the purpose of Kubernetes Secrets in relation to security?
Answer: To store sensitive data like passwords and tokens separately from Pod specs
Kubernetes Secrets store sensitive information (passwords, tokens, keys) separately from application code and Pod specs to reduce exposure.
Which securityContext field can be used to drop Linux capabilities from a container?
Answer: capabilities.drop
The `capabilities.drop` field in a container's securityContext specifies a list of Linux capabilities to remove from the container.
What is the role of an Admission Controller in Kubernetes security?
Answer: Intercepts API requests after authentication/authorization to validate or mutate them
Admission controllers intercept API requests after authentication and authorization, and can validate, mutate, or reject requests before the object is persisted.
Which RBAC verb allows a user to watch for real-time changes to a resource?
Answer: watch
The 'watch' verb in RBAC allows subjects to receive streaming updates when a resource changes, used by controllers and kubectl watch.
What does the 'restricted' Pod Security Standard level require that 'baseline' does not?
Answer: Requires running as non-root and dropping all capabilities
The 'restricted' level enforces additional hardening including running as non-root, dropping ALL capabilities, and requiring seccomp profiles.
In Kubernetes RBAC, which built-in ClusterRole provides read-only access to most resources?
Answer: view
The built-in 'view' ClusterRole grants read-only access (get, list, watch) to most namespaced resources but not to Secrets or RBAC resources.
What is the primary risk of using `hostPID: true` in a Pod spec?
Answer: It allows the container to see and interact with all host processes
Setting `hostPID: true` allows a Pod to share the host's process ID namespace, enabling it to see and potentially signal all processes running on the node.