---
tags:
- k8s
- l1
- flashcard-deck
- k8s-security
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [RBAC](../../../../library/portal/topics.md) | **Domain:** Kubernetes
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
k8s-security/04457adcdd92	k8s-security	easy	k8s-security, network-policy, rbac	True or False? If no network policies are applied to a pod, then no connections to or from it are allowed	False. By default, pods are non-isolated — all ingress and egress traffic is allowed. Network policies only take effect when explicitly applied, and they use a whitelist model: once any policy selects a pod, all traffic not explicitly allowed is denied. \nGotcha: NetworkPolicy requires a CNI plugin that supports it (Calico, Cilium), not all do.	projects/knowledge/interview/kubernetes/164-true-or-false-if-no-network-policies-are-applied-t.txt
k8s-security/055836c44ddf	k8s-security	hard	k8s-security, rbac, network-policy, pod-security	How does Kubernetes manage security, and what are some best practices?	**Kubernetes Security Management:**\n • Role-Based Access Control (RBAC): Defines and enforces access policies.\n • Pod Security Policies: Restricts pod behaviors for security compliance.\n • Network Policies: Controls communication between pods.\n • Secrets Management: Safely handles sensitive information.\n • Container Runtime Security: Ensures container runtime security practices.\n • Security Contexts: Defines security settings at the pod or container level.\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).	
k8s-security/0c607ddf5b07	k8s-security	easy	k8s-security, pod-security, admission-controller	What is PodSecurity and how can it be configured in a Kubernetes cluster?	* PodSecurity in Kubernetes: PodSecurity refers to policies and configurations that control the security context of pods.\n* It includes settings related to running as a privileged user, allowing privileged containers, and more.\n* PodSecurityPolicy was removed in K8s 1.25. Use the built-in Pod Security Admission controller with labels (enforce/audit/warn) and Pod Security Standards (privileged/baseline/restricted).\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).	projects/knowledge/interview/kubernetes/357-what-is-podsecurity-and-how-can-it-be-configured-i.txt
k8s-security/165d2a0d7707	k8s-security	medium	k8s-security, pod-security, admission-controller	Explain how Gatekeeper works	On every request sent to the Kubernetes cluster, Gatekeeper sends the policies and the resources to OPA (Open Policy Agent) to check if it violates any policy. If it does, Gatekeeper will return the policy error message back. If it isn't violates any policy, the request will reach the cluster.\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).	projects/knowledge/interview/kubernetes/249-explain-how-gatekeeper-works.txt
k8s-security/16f7aa6c5f03	k8s-security	medium	k8s-security, rbac, serviceaccount	Explain the role of RBAC (Role-Based Access Control) in Kubernetes.	* RBAC in Kubernetes: RBAC is a Kubernetes feature that defines roles, role bindings, and cluster roles to control access.\n* It enables administrators to grant permissions to users, groups, or service accounts based on roles.\n* RBAC enhances security by enforcing the principle of least privilege.\n\nRemember: RBAC = 4 objects: Role, ClusterRole, RoleBinding, ClusterRoleBinding. "2+2."	projects/knowledge/interview/kubernetes/356-explain-the-role-of-rbac-role-based-access-control.txt
k8s-security/1bf96461f144	k8s-security	medium	k8s-security, network-policy, rbac	What are some use cases for using Network Policies?	- Security:  You want to prevent from everyone to communicate with a certain pod for security reasons\n  - Controlling network traffic: You would like to deny network flow between two specific nodes\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).\n\nExample: Isolate a database pod so only the API pod can reach it: NetworkPolicy with ingress from pods labeled app=api.\n\nRemember: NetworkPolicies are additive — multiple policies on the same pod combine their allowed traffic.	projects/knowledge/interview/kubernetes/163-what-are-some-use-cases-for-using-network-policies.txt
k8s-security/2f06ba57c9f6	k8s-security	medium	k8s-security, pod-security, admission-controller	What is OPA Gatekeeper and how does it enforce policies in Kubernetes?	[Gatekeeper docs](https://open-policy-agent.github.io/gatekeeper/website/docs): "Gatekeeper is a validating (mutating TBA) webhook that enforces CRD-based policies executed by Open Policy Agent"\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).	projects/knowledge/interview/kubernetes/248-what-is-gatekeeper.txt
k8s-security/5671b39291d0	k8s-security	hard	k8s-security, network-policy, rbac	Explain the concept of Network Policies in Kubernetes.	* Network Policies: Network Policies in Kubernetes define how pods can communicate with each other.\n* They specify rules for ingress and egress traffic based on pod labels.\n* Network Policies help enforce security and segmentation within a cluster.\n* By defining Network Policies, administrators can control the flow of network traffic between pods. \n* This enhances security by restricting communication to only the necessary components, helping prevent unauthorized access or potential attacks within the cluster.\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).	projects/knowledge/interview/kubernetes/329-explain-the-concept-of-network-policies-in-kuberne.txt
k8s-security/5c399b8695b3	k8s-security	hard	k8s-security, pod-security, rbac	Discuss PodSecurityPolicies in Kubernetes and how they enhance security.	* PodSecurityPolicies (PSP): PSP is a cluster-level resource that controls security-sensitive aspects of pod specification.\n* It defines a set of conditions that a pod must run with.\n* PSP enhances security by restricting privilege escalation, host namespace usage, and more.\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).	projects/knowledge/interview/kubernetes/355-discuss-podsecuritypolicies-in-kubernetes-and-how-.txt
k8s-security/5faed00bd59a	k8s-security	medium	k8s-security, serviceaccount, rbac	Explain how Service Accounts are different from User Accounts	- User accounts are global while Service accounts unique per namespace\n  - User accounts are meant for humans or client processes while Service accounts are for processes which run in pods\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).	projects/knowledge/interview/kubernetes/232-explain-how-service-accounts-are-different-from-us.txt
k8s-security/78524e9a4b6a	k8s-security	easy	k8s-security, admission-controller, rbac	What is the purpose of an admission controller in Kubernetes, and how can you extend it?	* Admission Controller in Kubernetes:\n* Admission controllers validate and mutate Kubernetes resources before they are persisted. \nThey enforce policies and security measures.\n* Extending Admission Controllers:\n* Custom admission controllers can be created to enforce specific organization or application-specific policies.\n* Use the Kubernetes admission webhook mechanism to extend admission control.\n\nRemember: Admission controllers intercept API requests. Types: validating and mutating.\n\nExample: LimitRanger, PodSecurity, OPA/Gatekeeper — common admission controllers.	projects/knowledge/interview/kubernetes/369-what-is-the-purpose-of-an-admission-controller-in-.txt
k8s-security/7e7e746a558b	k8s-security	medium	k8s-security, pod-security, rbac	What is Conftest and how does it validate configuration files?	Conftest allows you to write tests against structured files. You can think of it as tests library for Kubernetes resources. \nIt is mostly used in testing environments such as CI pipelines or local hooks.\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).	projects/knowledge/interview/kubernetes/250-what-is-conftest.txt
k8s-security/804aaf801acd	k8s-security	easy	k8s-security, rbac, serviceaccount	What is the difference between Role and ClusterRole objects?	The difference between them is that a Role is used at a namespace level whereas a ClusterRole is for the entire cluster.\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).\n\nRemember: Role = namespaced permissions. ClusterRole = cluster-wide permissions. Same syntax, different scope.\n\nExample: Role in namespace dev can grant access to pods in dev only. ClusterRole can grant access to pods in ALL namespaces.\n\nGotcha: ClusterRoles can be referenced by RoleBindings (scoping them to one namespace) — a powerful pattern for reuse.	projects/knowledge/interview/kubernetes/229-what-is-the-difference-between-role-and-clusterrol.txt
k8s-security/81653c0d7595	k8s-security	medium	k8s-security, serviceaccount, rbac	What happens you create a pod and you DON'T specify a service account?	The pod is automatically assigned with the default service account (in the namespace where the pod is running).\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).	projects/knowledge/interview/kubernetes/231-what-happens-you-create-a-pod-and-you-dont-specify.txt
k8s-security/81dff17aa7bd	k8s-security	medium	k8s-security, rbac, pod-security	Give examples of recommended security measures for Kubernetes.	Examples of standard Kubernetes security measures include:\n\n* Defining resource quotas\n* Support for auditing\n* Restriction of etcd access\n* Regular security updates to the environment\n* Network segmentation\n* Definition of strict resource policies\n* Continuous scanning for security vulnerabilities\n* Using images from authorized repositories\n* Implementing RBAC (Role-Based Access Control)\n* Using Pod Security Policies or Pod Security Standards\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).	projects/knowledge/interview/kubernetes/411-give-examples-of-recommended-security.txt
k8s-security/c7f7601106c2	k8s-security	easy	k8s-security, serviceaccount, rbac	How to list Service Accounts?	`kubectl get serviceaccounts`\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).\n\nRemember: `kubectl get sa` (short for serviceaccounts). Every namespace has a default SA created automatically.\n\nGotcha: The default SA may have more permissions than you expect — always audit RoleBindings referencing it.	projects/knowledge/interview/kubernetes/233-how-to-list-service-accounts.txt
k8s-security/cc49bc17448a	k8s-security	hard	k8s-security, rbac, network-policy, pod-security	Discuss the best practices for securing a Kubernetes cluster.	**Best Practices for Kubernetes Security:**\n* Enforce RBAC to control access.\n* Regularly update Kubernetes and its components.\n* Use network policies for granular control.\n* Employ pod security policies for fine-grained security controls.\n* Monitor and audit cluster activities for anomalies.\n* Implement secure container images and runtime configurations.\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).	projects/knowledge/interview/kubernetes/365-discuss-the-best-practices-for-securing-a-kubernet.txt
k8s-security/d879c26ec994	k8s-security	medium	k8s-security, rbac, serviceaccount	What is RBAC (Role-Based Access Control) and how is it implemented?	RBAC in Kubernetes is the mechanism that enables you to configure fine-grained and specific sets of permissions that define how a given user, or group of users, can interact with any Kubernetes object in cluster, or in a specific Namespace of cluster.\n\nRemember: RBAC = 4 objects: Role, ClusterRole, RoleBinding, ClusterRoleBinding. "2+2."	projects/knowledge/interview/kubernetes/228-what-is-rbac.txt
k8s-security/e27c6204eb87	k8s-security	easy	k8s-security, pod-security, rbac	What is Datree? How is it different from Conftest?	Same as Conftest, it is used for policy testing and enforcement. The difference is that it comes with built-in policies.\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).\n\nRemember: Datree = Conftest + built-in policy library. Conftest = bring your own policies (Rego). Datree is easier to start; Conftest is more flexible.\n\nGotcha: Both tools validate YAML before deployment — they are not runtime enforcers like OPA Gatekeeper.	projects/knowledge/interview/kubernetes/251-what-is-datree-how-is-it-different-from-conftest.txt
k8s-security/e37fb114626e	k8s-security	medium	k8s-security, network-policy, rbac	Explain Network Policies	[kubernetes.io](https://kubernetes.io/docs/concepts/services-networking/network-policies): "NetworkPolicies are an application-centric construct which allow you to specify how a pod is allowed to communicate with various network "entities"..."\n\nIn simpler words, Network Policies specify how pods are allowed/disallowed to communicate with each other and/or other network endpoints.\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).	projects/knowledge/interview/kubernetes/162-explain-network-policies.txt
k8s-security/ed5520adff3a	k8s-security	medium	k8s-security, secrets, rbac	How do you implement encryption for data in transit and at rest in Kubernetes?	* Encryption in Kubernetes:\n* Data in Transit: Use Transport Layer Security (TLS) for encrypting communication between components and pods.\n* Data at Rest: Leverage storage providers that support encryption or use tools like dm-crypt for node-level encryption.\n* For secrets, use encryption mechanisms provided by Kubernetes, such as sealed secrets.\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).	projects/knowledge/interview/kubernetes/358-how-do-you-implement-encryption-for-data-in-transi.txt
k8s-security/f14d58e70617	k8s-security	hard	k8s-security, network-policy, rbac	Explain the concept of Network Policies in Kubernetes, and provide an example.	**Network Policies in Kubernetes:**\n* Network Policies are specifications that control the communication between pods.\n* They define rules to allow or deny traffic based on labels, namespaces, and pod selectors.\n* Network Policies enhance security by restricting communication between pods.\n```yaml\napiVersion: networking.k8s.io/v1\nkind: NetworkPolicy\nmetadata:\n  name: deny-all-ingress\nspec:\n  podSelector: {}\n  ingress: []\n```\n* This example denies all incoming traffic to pods within the namespace where the policy is applied.\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).	projects/knowledge/interview/kubernetes/353-explain-the-concept-of-network-policies-in-kuberne.txt
k8s-security/f460dc6d5bc6	k8s-security	medium	k8s-security, rbac, serviceaccount	Explain what are "Service Accounts" and in which scenario would use create/use one	[Kubernetes.io](https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account): "A service account provides an identity for processes that run in a Pod."\n\nAn example of when to use one:\nYou define a pipeline that needs to build and push an image. In order to have sufficient permissions to build an push an image, that pipeline would require a service account with sufficient permissions.\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).	projects/knowledge/interview/kubernetes/230-explain-what-are-service-accounts-and-in-which-sce.txt
k8s-security/f7f7cefb3ca0	k8s-security	medium	k8s-security, network-policy, rbac	Which Kubernetes concept would you use to control traffic flow at the IP address or port level?	Network Policies\n\nRemember: K8s security layers: RBAC (who), NetworkPolicy (what), PSA (how), encryption (data).\n\nRemember: NetworkPolicy = L3/L4 firewall for pods. Controls IP and port-level traffic between pods and external endpoints.\n\nGotcha: NetworkPolicies require a CNI plugin that supports them (Calico, Cilium). Flannel does NOT enforce them.	projects/knowledge/interview/kubernetes/123-which-kubernetes-concept-would-you-use-to-control-.txt
k8s-security/f81cdb5cc3b4	k8s-security	hard	k8s-security, pod-security, admission-controller	What security best practices do you follow in regards to the Kubernetes cluster?	* Secure inter-service communication (one way is to use Istio to provide mutual TLS)\n  * Isolate different resources into separate namespaces based on some logical groups\n  * Use supported container runtime (if you use Docker then drop it because it's deprecated. You might want to CRI-O as an engine and podman for CLI)\n  * Test properly changes to the cluster (e.g. consider using Datree to prevent kubernetes misconfigurations)\n  * Limit who can do what (by using for example OPA gatekeeper) in the cluster\n  * Use NetworkPolicy to apply network security\n  * Consider using tools (e.g.	projects/knowledge/interview/kubernetes/265-what-security-best-practices-do-you-follow-in-rega.txt
k8s-security/f8b2f5849915	k8s-security	medium	k8s-security, rbac, pod-security	Explain "Security Context"	[kubernetes.io](https://kubernetes.io/docs/tasks/configure-pod-container/security-context): "A security context defines privilege and access control settings for a Pod or Container."\n\nGotcha: PSP removed in K8s 1.25. Use Pod Security Admission (PSA): enforce, audit, warn.\n\nRemember: PSA levels: Privileged, Baseline, Restricted. Mnemonic: "PBR."	projects/knowledge/interview/kubernetes/234-explain-security-context.txt

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Interview: RBAC Forbidden](../../../../library/interview-scenarios/09-rbac-forbidden.md) (Scenario, L2) — RBAC
- [K8s RBAC](../../../../library/topics/k8s-rbac/index.md) (Topic Pack, L1) — RBAC
- Kubernetes Exercises (Quest Ladder) *(CLI)* (Exercise Set, L1) — RBAC
- Kubernetes RBAC Flashcards *(CLI)* (flashcard_deck, L1) — RBAC
- [Multi-Tenancy Patterns](../../../../library/topics/multi-tenancy/index.md) (Topic Pack, L2) — RBAC
- [Policy Engines (OPA / Kyverno)](../../../../library/topics/policy-engines/index.md) (Topic Pack, L2) — RBAC
- [Runbook: RBAC Forbidden](../../../../library/runbooks/kubernetes/rbac_forbidden.md) (Runbook, L2) — RBAC
- [Track: Kubernetes Core](../../../../library/curriculum/tracks/kubernetes_core.md) (Reference, L1) — RBAC

<!-- wiki:related:end -->
