- Home
- All questions
- Question 19
CKA study material · question 19 of 1000
A team wants to revoke a permission that a broad Role already grants, by adding a second, narrower Role. Why will that not work?
Show the answer
Answer: A. RBAC permissions are purely additive and there are no deny rules
RBAC only ever adds access; a permission cannot be subtracted by writing another Role.
Source: Using RBAC Authorization (Kubernetes) — Role and ClusterRole