Security and RBAC Flashcards
7 cards from real KCNA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security and RBAC flashcards as text
Which Kubernetes object binds a ClusterRole to a user across all namespaces?
Answer: ClusterRoleBinding
A ClusterRoleBinding grants the permissions defined in a ClusterRole to a subject across all namespaces in the cluster.
What is the default behavior for a Pod that does not specify a ServiceAccount?
Answer: The 'default' ServiceAccount in its namespace is used
When a Pod does not specify a ServiceAccount, it automatically uses the 'default' ServiceAccount in its namespace.
Which field in a Pod spec controls whether the ServiceAccount token is auto-mounted?
Answer: automountServiceAccountToken
The `automountServiceAccountToken` field in the Pod spec (or ServiceAccount spec) controls whether the token is automatically mounted.
In Kubernetes RBAC, what does a 'verb' represent in a PolicyRule?
Answer: The action allowed on a resource (e.g., get, list, delete)
Verbs in RBAC PolicyRules represent HTTP-method-like actions such as get, list, watch, create, update, patch, and delete.
Which admission controller is responsible for enforcing Pod Security Standards?
Answer: PodSecurity
The PodSecurity admission controller, introduced in Kubernetes 1.22, enforces Pod Security Standards at the namespace level.
What does the 'privileged' Pod Security Standard level allow?
Answer: Unrestricted policies, equivalent to no policy
The 'privileged' level is intentionally unrestricted and allows known privilege escalations, equivalent to running without any pod security enforcement.
Which Kubernetes resource type is used to define reusable RBAC permissions that can be scoped to a single namespace?
Answer: Role
A Role defines a set of permissions within a specific namespace and cannot grant access to cluster-scoped resources.