Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium
A security engineer is configuring a Kubernetes cluster to enforce strict security policies for all new Pods. They want to ensure that no Pod runs as root, has privileged access, or mounts host paths. This policy must be enforced at the cluster level, preventing non-compliant Pods from even being created. Which Kubernetes feature is designed for this purpose?
- APod Security Admission (PSA)
- BHorizontal Pod Autoscaler (HPA)
- CNetworkPolicy
- DRole-Based Access Control (RBAC)
Show answer & explanationAnswer & explanation
Correct answer: A. Pod Security Admission (PSA)
Pod Security Admission (PSA) is a built-in Kubernetes feature that enforces Pod Security Standards (PSS) at the namespace level, preventing the creation of Pods that violate predefined security profiles like 'restricted' or 'baseline'.
Why the other options are wrong
- B. HPA scales Pods based on resource usage, unrelated to security policies.
- C. NetworkPolicy controls network traffic, not Pod security contexts.
- D. RBAC controls who can perform actions (like creating Pods), not the security posture of the Pods themselves.
Pod Security Admission (PSA)
A built-in Kubernetes admission controller that enforces Pod Security Standards (PSS) on Pods at the namespace level, ensuring Pods adhere to predefined security policies before being admitted to the cluster.
- Replaces Pod Security Policies (PSPs).
- Enforces 'priviliged', 'baseline', or 'restricted' profiles.
- Operates at the admission control phase.
- Configured per namespace using labels.
Memory trick: PSA secures Pod admission.