Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsHard
A cluster administrator is performing a security audit and wants to ensure that no Pods are running with root privileges within the cluster. Which security feature should they configure to enforce this policy across all namespaces?
- ASecrets
- BNetworkPolicy
- CPod Security Standards (PSS)
- DRole-Based Access Control (RBAC)
Show answer & explanationAnswer & explanation
Correct answer: C. Pod Security Standards (PSS)
Pod Security Standards (PSS) define three security levels (Privileged, Baseline, Restricted) that can be enforced via Admission Controllers. By configuring an appropriate PSS policy (e.g., 'Restricted') at the cluster or namespace level, the administrator can prevent Pods from running with root privileges.
Why the other options are wrong
- A. Secrets store sensitive data but do not enforce Pod security policies.
- B. NetworkPolicy controls network traffic, not Pod security contexts.
- D. RBAC controls API access, not the security context of Pods themselves.
Pod Security Standards (PSS)
A set of policies that define different levels of security for Pods, ranging from highly permissive to highly restrictive, enforced via Admission Controllers.
- Defines Pod security levels (Privileged, Baseline, Restricted).
- Enforced by Admission Controllers.
- Replaces Pod Security Policies (PSPs).
Memory trick: PSS: Pods Stay Secure!