Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium

A security engineer is configuring a Kubernetes cluster to enforce strict security policies for all Pods. They want to ensure that Pods cannot run as a privileged user, cannot use host namespaces, and must use a read-only root filesystem. Which Kubernetes security mechanism, configured at the namespace or cluster level, is designed to enforce these kinds of baseline security standards?

  1. AKubernetes NetworkPolicy
  2. BPod Security Admission (PSA)
  3. CRole-Based Access Control (RBAC)
  4. DValidating Admission Webhooks
Show answer & explanation

Correct answer: B. Pod Security Admission (PSA)

Pod Security Admission (PSA) allows enforcement of Pod Security Standards (PSS) at the namespace or cluster level. PSS defines three levels (Privileged, Baseline, Restricted) that directly address requirements like preventing privileged containers, host namespaces, and enforcing read-only root filesystems.

Why the other options are wrong

  • A. Kubernetes NetworkPolicy controls network traffic, not Pod security contexts.
  • C. RBAC controls user and service account permissions to interact with Kubernetes API objects, not the security context of Pods.
  • D. Validating Admission Webhooks can enforce custom policies, but PSA is the built-in, standardized mechanism for enforcing Pod Security Standards.

Pod Security Admission (PSA)

A built-in Kubernetes admission controller that enforces Pod Security Standards (PSS) on Pods based on their namespace labels, providing a standardized way to apply security best practices.

  • Enforces Pod Security Standards (PSS).
  • Operates at the namespace or cluster level.
  • Offers `Privileged`, `Baseline`, and `Restricted` profiles.

Memory trick: PSA admits Pods only if they meet security standards.

More Cloud Native Security questions