Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsMedium

A security auditor is reviewing the default access controls within a Kubernetes cluster. They notice that individual users and service accounts are granted specific permissions to perform actions on Kubernetes resources like Pods, Deployments, and Services. Which Kubernetes security mechanism is primarily responsible for defining and enforcing these permissions?

  1. ASecrets
  2. BNetworkPolicy
  3. CPod Security Standards (PSS)
  4. DRole-Based Access Control (RBAC)
Show answer & explanation

Correct answer: D. Role-Based Access Control (RBAC)

Role-Based Access Control (RBAC) is the primary Kubernetes authorization mechanism that regulates who (users or service accounts) can perform what actions (verbs) on which resources (nouns) in a given namespace or cluster-wide.

Why the other options are wrong

  • A. Secrets are used to store sensitive data; they are a resource that RBAC can control access to, but not the mechanism itself.
  • B. NetworkPolicy controls network traffic flow between Pods, not access to Kubernetes API resources.
  • C. Pod Security Standards (PSS) define security best practices for Pods, not user/service account permissions.

Role-Based Access Control (RBAC)

RBAC is a method of regulating access to computer or network resources based on the roles of individual users within an enterprise.

  • Uses Roles (permissions) and RoleBindings (assigns roles to subjects).
  • Can be applied at namespace-level (Role) or cluster-level (ClusterRole).
  • Subjects can be users, groups, or service accounts.
  • Essential for securing Kubernetes API access.

Memory trick: Roles Define, Bindings Assign, PSS Secures, Network Isolates.

More Kubernetes Fundamentals questions