CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security auditor is reviewing the hardening configuration of a Kubernetes cluster. The organization mandates strict security policies for all pods, including restricting privileged containers, preventing hostPath volume mounts, and ensuring immutable file systems. These policies must be enforced at the cluster level before any pod is allowed to run. Which Kubernetes admission controller is BEST suited to enforce these types of pod-level security best practices?
- APod Security Admission (PSA)
- BResourceQuota
- CLimitRange
- DNetworkPolicy
Show answer & explanationAnswer & explanation
Correct answer: A. Pod Security Admission (PSA)
Pod Security Admission (PSA) is a native Kubernetes admission controller that enforces Pod Security Standards (PSS) at the namespace level, providing predefined security profiles (Privileged, Baseline, Restricted) to enforce policies like restricting privileged containers, hostPath mounts, and immutable file systems, directly matching the requirement.
Why the other options are wrong
- B. ResourceQuota limits resource consumption (CPU, memory, object count) within a namespace, unrelated to pod security best practices.
- C. LimitRange sets default resource requests and limits for pods and containers within a namespace, not security policies.
- D. NetworkPolicy controls network traffic flow between pods and other network endpoints, not the security configuration of the pods themselves.
Pod Security Admission (PSA)
A native Kubernetes admission controller that enforces Pod Security Standards (PSS) by applying predefined security profiles (Privileged, Baseline, Restricted) to pods at the namespace level.
- Enforces security best practices for pods
- Offers three predefined policy levels: Privileged, Baseline, Restricted
- Replaces the deprecated Pod Security Policy (PSP)
Memory trick: PSA: Pods Securely Admitted.