Question 1
You are hardening a high-availability cluster whose control plane nodes run stacked etcd. After inspecting the static pod manifests in /etc/kubernetes/manifests/, you notice the etcd pod definition is missing a critical parameter for secure communication between members. Which of the following parameters, when correctly configured, ensures that etcd members properly authenticate each other?
Answer and explanation
Correct answer: C
--peer-client-cert-auth=true makes an etcd member check that every incoming peer request (port 2380) presents a valid client certificate signed by the peer CA (--peer-trusted-ca-file). The flag defaults to false, and the etcd docs recommend enabling it to block unauthenticated, forged peers. kubeadm sets it to true in the etcd static Pod, together with --peer-cert-file and --peer-key-file. --listen-client-urls and --advertise-client-urls concern client traffic on port 2379, and --initial-cluster-state (new or existing) only matters when a member bootstraps.