BlackFriday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Linux Foundation Exam CKS Topic 3 Question 68 Discussion

Actual exam question for Linux Foundation's CKS exam
Question #: 68
Topic #: 3
[All CKS Questions]

Fix all issues via configuration and restart the affected components to ensure the new setting takes effect.

Fix all of the following violations that were found against theAPI server:-

a. Ensure that the RotateKubeletServerCertificate argument is set to true.

b. Ensure that the admission control plugin PodSecurityPolicy is set.

c. Ensure that the --kubelet-certificate-authority argument is set as appropriate.

Fix all of the following violations that were found against theKubelet:-

a. Ensure the --anonymous-auth argument is set to false.

b. Ensure that the --authorization-mode argument is set to Webhook.

Fix all of the following violations that were found against theETCD:-

a. Ensure that the --auto-tls argument is not set to true

b. Ensure that the --peer-auto-tls argument is not set to true

Hint: Take the use of Tool Kube-Bench

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

Lore
30 days ago
Rotate the kubelet server cert? That's a new one to me. I wonder if there's a good reason why they're specifically calling that out.
upvoted 0 times
Ludivina
19 hours ago
Yeah, it helps prevent unauthorized access and ensures a higher level of security.
upvoted 0 times
...
Delsie
6 days ago
It's important for security reasons to rotate the kubelet server certificate regularly.
upvoted 0 times
...
...
Salina
1 months ago
I bet the exam proctors are sitting back and laughing at us as we struggle to figure out the right combination of settings. Gotta love these Kubernetes security audits!
upvoted 0 times
Lorenza
2 days ago
I think we just need to carefully follow the instructions and make sure we get everything right.
upvoted 0 times
...
Jina
16 days ago
I know, these security audits can be so tricky!
upvoted 0 times
...
...
Viola
1 months ago
Yes, and we should also ensure that the admission control plugin PodSecurityPolicy is set.
upvoted 0 times
...
Nakisha
1 months ago
I agree, setting RotateKubeletServerCertificate to true is crucial for security.
upvoted 0 times
...
Svetlana
1 months ago
Ah, the classic 'fix all the things' kind of question. At least they threw in a hint about using Kube-Bench - that should make our lives a bit easier.
upvoted 0 times
...
Florinda
2 months ago
Hold up, is that really all there is to it? What if there are dependencies between these settings? We better double-check the documentation to make sure we're not missing anything.
upvoted 0 times
Torie
14 days ago
Let's review the documentation carefully before making any changes.
upvoted 0 times
...
Mari
20 days ago
I agree, it's always best to be thorough when making configuration changes.
upvoted 0 times
...
Cordelia
1 months ago
Good point, we don't want to overlook anything important.
upvoted 0 times
...
Blythe
1 months ago
We should definitely double-check the documentation to make sure we're not missing any dependencies.
upvoted 0 times
...
...
Leota
2 months ago
I think we need to fix the violations against the API server first.
upvoted 0 times
...
Fannie
2 months ago
Hmm, the solution looks pretty straightforward. Just need to configure the right arguments on the API server, kubelet, and etcd components.
upvoted 0 times
Shawnta
29 days ago
Yes, we just need to make sure we set the correct arguments and restart the components.
upvoted 0 times
...
Allene
1 months ago
I agree, it seems like a simple fix. Just follow the instructions provided.
upvoted 0 times
...
...

Save Cancel