CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security engineer is tasked with hardening a new Kubernetes cluster. The organization requires that all container images deployed to the cluster originate from an approved, scanned registry and are cryptographically signed. Any attempt to deploy an unsigned or unapproved image must be automatically rejected. Which Kubernetes admission controller or feature is BEST suited to enforce this policy?

  1. AResourceQuotas
  2. BNetworkPolicy
  3. CImagePolicyWebhook
  4. DPod Security Admission (PSA)
Show answer & explanation

Correct answer: C. ImagePolicyWebhook

ImagePolicyWebhook is a Kubernetes admission controller that allows an external webhook service to validate or mutate image references in admission requests. This enables enforcement of policies like requiring signed images from approved registries before deployment.

Why the other options are wrong

  • A. ResourceQuotas manage resource consumption (CPU, memory) within namespaces, unrelated to image security policies.
  • B. NetworkPolicy controls network traffic flow between pods/namespaces, not image validation.
  • D. Pod Security Admission (PSA) enforces pod security standards, focusing on pod configuration like privilege escalation, not image origin or signing.

ImagePolicyWebhook

A Kubernetes admission controller that allows an external service to validate or mutate image references in admission requests, enabling policies like requiring signed images.

  • Intercepts image deployment requests
  • Delegates validation to an external webhook service
  • Enforces policies on image origin, signing, and content

Memory trick: Image Policy Webhook: Images checked at the gate.

More Security Engineering questions