Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium
A security engineer is configuring Pod Security Admission (PSA) for a new Kubernetes namespace. They want to ensure that all Pods deployed in this namespace adhere to a baseline level of security, preventing common privilege escalation techniques while allowing some flexibility for applications. Which PSA enforcement mode should be applied to the namespace?
- ARestricted
- BBaseline
- CEnforce
- DPrivileged
Show answer & explanationAnswer & explanation
Correct answer: B. Baseline
The 'Baseline' Pod Security Standard is designed to prevent known privilege escalations while allowing most common application workloads to run without modification. It strikes a balance between security and compatibility, fitting the requirement for 'some flexibility'.
Why the other options are wrong
- A. The 'Restricted' mode enforces heavily hardened Pods, requiring more effort to configure applications and offering less flexibility.
- C. 'Enforce' is an action mode (like 'audit' or 'warn'), not a security standard level itself.
- D. The 'Privileged' mode imposes no restrictions and is the least secure.
Pod Security Standards (PSS)
A set of predefined security policies in Kubernetes that define different levels of Pod isolation and restriction, from highly permissive to highly restrictive, to help users enforce security best practices.
- Three levels: Privileged, Baseline, Restricted.
- Enforced by Pod Security Admission (PSA).
- Helps prevent common security vulnerabilities in Pods.
Memory trick: Privileged is wide open, Baseline is good enough, Restricted is locked down tight.