CompTIA SecurityX (CAS-005)Security EngineeringHard

A security engineer is tasked with hardening a new Kubernetes cluster. The organization requires that all container images deployed to the cluster must originate from trusted, scanned repositories and remain immutable. Which Kubernetes security admission controller should the engineer configure to enforce this policy?

  1. AAlwaysPullImages
  2. BNodeRestriction
  3. CImagePolicyWebhook
  4. DPodSecurityAdmission
Show answer & explanation

Correct answer: C. ImagePolicyWebhook

The ImagePolicyWebhook admission controller allows an external webhook service to validate and mutate image references. This enables organizations to implement custom policies, such as ensuring images come from trusted registries, are signed, or have passed vulnerability scans, before they are allowed to run in the cluster. PodSecurityAdmission enforces a predefined set of security standards for Pods, but not specifically image origin or immutability checks via external services.

Why the other options are wrong

  • A. AlwaysPullImages ensures fresh images are pulled, but doesn't validate their origin or integrity against a policy.
  • B. NodeRestriction restricts kubelet access to only modify Pods on its own node, not image policies.
  • D. PodSecurityAdmission enforces security standards on Pods but doesn't directly manage the source or immutability verification of container images via external validation services.

ImagePolicyWebhook

The ImagePolicyWebhook is a Kubernetes admission controller that sends image information to an external webhook service for validation and mutation.

  • Enables custom image admission policies.
  • Integrates with external scanning and signing services.
  • Can prevent untrusted images from running in the cluster.

Memory trick: Images are verified by a webhook, like a bouncer at the club.

More Security Engineering questions