CompTIA SecurityX (CAS-005)Security EngineeringHard
A security auditor is reviewing the hardening configuration of a Kubernetes cluster used for sensitive production workloads. The auditor identifies that the cluster's default admission controller policies are too permissive, allowing containers to run with root privileges and mount host paths. To enforce a more secure baseline, the auditor recommends implementing a mechanism that intercepts and validates requests to the Kubernetes API server before objects are persisted, ensuring they comply with security best practices. Which Kubernetes security mechanism should be configured to achieve this enforcement?
- ASecrets Management
- BPod Security Admission (PSA)
- CNetwork Policies
- DRole-Based Access Control (RBAC)
Show answer & explanationAnswer & explanation
Correct answer: B. Pod Security Admission (PSA)
Pod Security Admission (PSA) is a built-in Kubernetes admission controller that enforces Pod Security Standards (PSS) by intercepting requests to the API server and validating them against predefined security profiles (Privileged, Baseline, Restricted). This directly addresses the need to prevent privileged containers and host path mounts.
Why the other options are wrong
- A. Secrets Management handles the secure storage and retrieval of sensitive information like API keys, not the runtime security context of pods.
- C. Network Policies control network communication between pods and other endpoints, not the security context or privileges of the pods themselves.
- D. RBAC controls who can do what (authorization) within the Kubernetes API, but it doesn't enforce the security posture of the workloads being deployed.
Pod Security Admission (PSA)
A built-in Kubernetes admission controller that enforces Pod Security Standards (PSS) at the namespace level, preventing the creation of pods that do not meet specified security profiles (Privileged, Baseline, Restricted).
- Enforces security best practices for pods.
- Operates as an admission controller in the API server.
- Replaces the deprecated Pod Security Policies (PSP).
Memory trick: PSA Prevents Risky Pods Actively.