CompTIA SecurityX (CAS-005)Security EngineeringHard
A security auditor is reviewing the hardening configuration of a Kubernetes cluster. The auditor identifies a requirement to restrict the types of container images that can be deployed to the cluster, ensuring that only images from approved, trusted registries are allowed. Which native Kubernetes admission controller should the auditor recommend to enforce this policy?
- ANodeRestriction
- BPodSecurityPolicy (deprecated)
- CImagePolicyWebhook
- DAlwaysPullImages
Show answer & explanationAnswer & explanation
Correct answer: C. ImagePolicyWebhook
The ImagePolicyWebhook admission controller allows external webhooks to determine if an image is allowed to be used. This provides a flexible and extensible way to enforce policies on container images, such as restricting deployments to only trusted registries, which is a critical security control for Kubernetes.
Why the other options are wrong
- A. NodeRestriction restricts kubelets to only modify Pods and Nodes they are assigned to, not for image policy enforcement.
- B. PodSecurityPolicy (PSP) was deprecated in Kubernetes 1.25 and is replaced by Pod Security Admission (PSA); while PSP could enforce some image-related policies, ImagePolicyWebhook is more specific and flexible for trusted registry enforcement.
- D. AlwaysPullImages forces Kubernetes to pull images every time a Pod is created, ensuring up-to-date images but not enforcing image source restrictions.
ImagePolicyWebhook
A Kubernetes admission controller that allows external HTTP callbacks (webhooks) to validate or mutate admission requests for container images, enabling custom image policy enforcement.
- Kubernetes admission controller
- Uses external webhooks
- Enforces image-related policies
- Can restrict images to trusted registries
Memory trick: ImagePolicyWebhook: The gatekeeper for trusted container images.