Exam CKS Topic 4 Question 1 Discussion
Actual exam question for Linux Foundation's CKS exam
Question #: 1
Topic #: 4
Question #: 1
Topic #: 4
You have a Kubernetes cluster with multiple namespaces, each representing a different department You need to ensure that resources in one namespace cannot access resources in another namespace, even if they are running as the same user. How would you implement this isolation policy and what are the potential risks if this isolation is not implemented effectively?
Suggested Answer:
Solution (Step by Step) :
1. Use Network Policies: Define network policies at the namespace level to control communication between pods. Each namespace will have its own
set of policies.
- Example Network Policy (Namespace A):

2. Enable Pod Security Policies (PSPsy PSPs allow you to define security constraints for pods running in your cluster. You can restrict the use of specific resources, capabilities, and network access. - Example PSP:

3. Isolate Resources: Ensure resources are not shared between namespaces, such as storage (persistent volumes) and configuration (config maps, secrets). - Example: Create separate persistent volumes and claims for each namespace. 4. Monitoring and Auditing: Implement monitoring and auditing tools to detect any unauthorized access attempts or violations of your isolation policy. 5. Potential Risks of Insufficient Isolation: - Data Breaches: Data in one namespace could be compromised by applications in another namespace, leading to a data leak. - Denial of Service: Applications in one namespace could consume all available resources, impacting the performance of applications in other namespaces. - Privilege Escalation: An application in one namespace could gain elevated privileges and access resources in other namespaces.
1. Use Network Policies: Define network policies at the namespace level to control communication between pods. Each namespace will have its own
set of policies.
- Example Network Policy (Namespace A):

2. Enable Pod Security Policies (PSPsy PSPs allow you to define security constraints for pods running in your cluster. You can restrict the use of specific resources, capabilities, and network access. - Example PSP:

3. Isolate Resources: Ensure resources are not shared between namespaces, such as storage (persistent volumes) and configuration (config maps, secrets). - Example: Create separate persistent volumes and claims for each namespace. 4. Monitoring and Auditing: Implement monitoring and auditing tools to detect any unauthorized access attempts or violations of your isolation policy. 5. Potential Risks of Insufficient Isolation: - Data Breaches: Data in one namespace could be compromised by applications in another namespace, leading to a data leak. - Denial of Service: Applications in one namespace could consume all available resources, impacting the performance of applications in other namespaces. - Privilege Escalation: An application in one namespace could gain elevated privileges and access resources in other namespaces.
by Viola at Jan 10, 2026, 08:29 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).