CompTIA SecurityX (CAS-005)Security EngineeringHard
A security auditor is reviewing the hardening configuration of a Kubernetes cluster. The auditor finds that while Pod Security Standards (PSS) are enforced, there is no mechanism to ensure that container images are scanned for vulnerabilities and signed before deployment. Which Kubernetes admission controller, when combined with an external policy engine, would be MOST effective in enforcing these additional security requirements?
- AValidatingWebhookConfiguration
- BResourceQuota
- CNodeRestriction
- DPodSecurity
Show answer & explanationAnswer & explanation
Correct answer: A. ValidatingWebhookConfiguration
ValidatingWebhookConfiguration is a Kubernetes admission controller that allows the cluster to send admission requests to an external webhook service for validation. This external service (e.g., OPA Gatekeeper, Kyverno) can then enforce complex, custom policies such as requiring image vulnerability scans or digital signatures, directly addressing the auditor's findings beyond PSS.
Why the other options are wrong
- B. ResourceQuota limits resource consumption (CPU, memory) per namespace, which is unrelated to image content or signing.
- C. NodeRestriction limits the API objects that kubelets can modify, primarily for security between nodes, not for image policy enforcement.
- D. PodSecurity enforces the built-in Pod Security Standards (PSS), which focus on pod configuration, not image content or signing.
ValidatingWebhookConfiguration
A Kubernetes admission controller that allows custom, external policy engines to validate or mutate API requests (like pod creation) before they are admitted to the cluster.
- Extends Kubernetes policy enforcement
- Integrates with external policy engines (e.g., OPA Gatekeeper)
- Enforces custom rules beyond built-in admission controllers
Memory trick: Validating Webhook: If it's not valid, the webhook will make it sad!