Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium

A security engineer is configuring Pod Security Admission (PSA) for a new Kubernetes namespace. They want to ensure that all Pods deployed in this namespace adhere to a baseline level of security, preventing common privilege escalation techniques while allowing some flexibility for applications. Which PSA enforcement mode should be applied to the namespace?

  1. ARestricted
  2. BBaseline
  3. CEnforce
  4. DPrivileged
Show answer & explanation

Correct answer: B. Baseline

The 'Baseline' Pod Security Standard is designed to prevent known privilege escalations while allowing most common application workloads to run without modification. It strikes a balance between security and compatibility, fitting the requirement for 'some flexibility'.

Why the other options are wrong

  • A. The 'Restricted' mode enforces heavily hardened Pods, requiring more effort to configure applications and offering less flexibility.
  • C. 'Enforce' is an action mode (like 'audit' or 'warn'), not a security standard level itself.
  • D. The 'Privileged' mode imposes no restrictions and is the least secure.

Pod Security Standards (PSS)

A set of predefined security policies in Kubernetes that define different levels of Pod isolation and restriction, from highly permissive to highly restrictive, to help users enforce security best practices.

  • Three levels: Privileged, Baseline, Restricted.
  • Enforced by Pod Security Admission (PSA).
  • Helps prevent common security vulnerabilities in Pods.

Memory trick: Privileged is wide open, Baseline is good enough, Restricted is locked down tight.

More Cloud Native Security questions