Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard

A platform engineering team is setting up a new Kubernetes cluster and needs to implement a custom security policy: all Pods must have a specific security context configured, disallowing privilege escalation and ensuring read-only root filesystems. They want this policy to be automatically enforced for all new Pods, and any Pods failing to meet this standard should be rejected. Which Kubernetes component should they use to achieve this enforcement?

  1. AKubernetes Role-Based Access Control (RBAC)
  2. BKubernetes NetworkPolicy
  3. CPod Security Admission (PSA)
  4. DValidating Admission Webhooks
Show answer & explanation

Correct answer: D. Validating Admission Webhooks

Validating Admission Webhooks are the correct choice for enforcing custom, fine-grained security policies not covered by built-in Admission Controllers or PSA. They allow external services to intercept API requests (like Pod creation) and reject them if they violate specific rules, such as requiring particular security context settings.

Why the other options are wrong

  • A. RBAC controls who can perform actions on Kubernetes resources, not the content or configuration of the resources themselves.
  • B. NetworkPolicy controls network traffic between Pods and namespaces, not Pod security contexts or admission control.
  • C. PSA enforces Pod Security Standards (Privileged, Baseline, Restricted) which are predefined. While it can enforce read-only root filesystems and disallow privilege escalation, a 'specific security context configured' implies a potentially more granular or custom set of rules beyond the standard PSA profiles, making Validating Admission Webhooks more flexible for truly custom policies.

Validating Admission Webhooks

A mechanism in Kubernetes that allows external HTTP callbacks to intercept and validate requests to the Kubernetes API server before persistence, enabling the enforcement of custom policies.

  • Intercepts API requests (e.g., Pod creation).
  • Can reject requests that violate defined policies.
  • Used for custom, dynamic policy enforcement not covered by built-in controllers.

Memory trick: Webhooks validate to halt bad configurations.

More Cloud Native Security questions