Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard

A security architect is designing a multi-tenant Kubernetes cluster. To ensure strong isolation and prevent privilege escalation, they want to limit the capabilities available to containers, disallow privileged containers, and restrict sensitive hostPath mounts. Which Kubernetes security primitive, when configured via an Admission Controller, is specifically designed to enforce these types of pod-level security constraints?

  1. ACustom Resource Definition (CRD)
  2. BPod Security Admission (PSA)
  3. CNetworkPolicy
  4. DResourceQuota
Show answer & explanation

Correct answer: B. Pod Security Admission (PSA)

Pod Security Admission (PSA) is the native Kubernetes mechanism for enforcing pod security standards. It allows cluster administrators to define different security levels (Privileged, Baseline, Restricted) for namespaces, which then control the security context of pods deployed within those namespaces, including capabilities, privileged mode, and hostPath mounts.

Why the other options are wrong

  • A. CRDs define custom resources but are not a security primitive for enforcing pod security standards directly.
  • C. NetworkPolicy controls network traffic, not pod security contexts.
  • D. ResourceQuota limits resource consumption (CPU, memory), not security capabilities.

Pod Security Admission (PSA)

A built-in Kubernetes admission controller that enforces Pod Security Standards (PSS) on pods, ensuring they meet defined security profiles.

  • Replaces deprecated PodSecurityPolicies (PSPs).
  • Enforces 'Privileged', 'Baseline', and 'Restricted' profiles.
  • Configured per namespace, applies to all pods in that namespace.
  • Controls capabilities, privileged mode, hostPath, SELinux, seccomp, etc.

Memory trick: PSA protects your pods from bad actors.

More Cloud Native Security questions