CompTIA SecurityX (CAS-005)Security EngineeringHard
A security engineer is tasked with hardening a new Kubernetes cluster. The organization requires that all container images deployed to the cluster must come from approved, trusted registries and must not contain known vulnerabilities or unapproved software. Which Kubernetes admission controller should be configured to enforce these policies at the point of deployment?
- AImagePolicyWebhook
- BResourceQuota
- CLimitRange
- DNodeRestriction
Show answer & explanationAnswer & explanation
Correct answer: A. ImagePolicyWebhook
ImagePolicyWebhook is a Kubernetes admission controller that allows an external webhook service to validate or mutate image requests before they are admitted to the cluster. This enables enforcement of policies like requiring images from trusted registries, scanning for vulnerabilities, or mandating specific image tags, directly addressing the organization's requirements at deployment time.
Why the other options are wrong
- B. ResourceQuota limits resource consumption (CPU, memory) per namespace, not image content or source.
- C. LimitRange sets default resource requests/limits for pods within a namespace, not image validation.
- D. NodeRestriction limits the API objects that kubelets can modify, primarily for security between nodes, not for image policy enforcement.
ImagePolicyWebhook
A Kubernetes admission controller that delegates image validation to an external webhook service, enforcing policies on container images before they are admitted to a cluster.
- Kubernetes admission controller
- External webhook validates image source/content
- Enforces policies like trusted registries, vulnerability scans
Memory trick: Image Policy Webhook: If your image isn't right, it won't take flight!