Skip to content
KCSA
Kubernetes Threat Model
medium
Question 2 of 32

Why is granting permission to create Pods or workload resources in a namespace considered a privilege-escalation risk?

AIt implicitly grants the ability to edit the API server manifest
BIt can expose Secrets, ConfigMaps, volumes, and the permissions of ServiceAccounts in that namespace
CIt disables Pod Security Admission automatically
DIt forces the kubelet to trust anonymous requests

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion