โ† All KCNA Flashcard Decks

Security and RBAC Flashcards

7 cards from real KCNA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security and RBAC flashcards as text
  1. What is the purpose of Kubernetes Secrets in relation to security?

    Answer: To store sensitive data like passwords and tokens separately from Pod specs

    Kubernetes Secrets store sensitive information (passwords, tokens, keys) separately from application code and Pod specs to reduce exposure.

  2. Which securityContext field can be used to drop Linux capabilities from a container?

    Answer: capabilities.drop

    The `capabilities.drop` field in a container's securityContext specifies a list of Linux capabilities to remove from the container.

  3. What is the role of an Admission Controller in Kubernetes security?

    Answer: Intercepts API requests after authentication/authorization to validate or mutate them

    Admission controllers intercept API requests after authentication and authorization, and can validate, mutate, or reject requests before the object is persisted.

  4. Which RBAC verb allows a user to watch for real-time changes to a resource?

    Answer: watch

    The 'watch' verb in RBAC allows subjects to receive streaming updates when a resource changes, used by controllers and kubectl watch.

  5. What does the 'restricted' Pod Security Standard level require that 'baseline' does not?

    Answer: Requires running as non-root and dropping all capabilities

    The 'restricted' level enforces additional hardening including running as non-root, dropping ALL capabilities, and requiring seccomp profiles.

  6. In Kubernetes RBAC, which built-in ClusterRole provides read-only access to most resources?

    Answer: view

    The built-in 'view' ClusterRole grants read-only access (get, list, watch) to most namespaced resources but not to Secrets or RBAC resources.

  7. What is the primary risk of using `hostPID: true` in a Pod spec?

    Answer: It allows the container to see and interact with all host processes

    Setting `hostPID: true` allows a Pod to share the host's process ID namespace, enabling it to see and potentially signal all processes running on the node.