200-901 Application Deployment and Security Practice Question
A company is deploying a containerized application to a Kubernetes cluster. The security team requires that the container runs as a non-root user and that the root filesystem is read-only. Which Kubernetes security context settings should be applied to the pod specification to meet these requirements?
⚠ Common exam trap
The trap here is assuming that allowPrivilegeEscalation: false or privileged: false automatically ensures the container runs as non-root, when they do not.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
securityContext: { runAsNonRoot: true, readOnlyRootFilesystem: true }
To enforce that a container runs as a non-root user, the securityContext must include runAsNonRoot: true. To make the root filesystem read-only, readOnlyRootFilesystem: true must be set. These can be combined in a single securityContext block. Other settings like allowPrivilegeEscalation or privileged do not guarantee non-root execution, so they are not sufficient.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
securityContext: { runAsUser: 0, readOnlyRootFilesystem: true }
Why it's wrong here
Setting runAsUser to 0 explicitly runs the container as the root user, which violates the requirement to run as non-root. While readOnlyRootFilesystem is correctly set, the runAsUser setting defeats the purpose. The security team's requirement is not met.
- ✗
securityContext: { privileged: false, readOnlyRootFilesystem: true }
Why it's wrong here
privileged: false is the default and does not prevent the container from running as root. It only disallows privileged mode, which grants access to all devices. The requirement to run as non-root is not addressed. Thus, this setting alone is insufficient.
- ✗
securityContext: { allowPrivilegeEscalation: false, readOnlyRootFilesystem: true }
Why it's wrong here
allowPrivilegeEscalation: false prevents a process from gaining more privileges than its parent, which is good practice, but it does not enforce running as a non-root user. The container could still run as root. Therefore, this does not fully satisfy the requirement to run as non-root.
- ✓
securityContext: { runAsNonRoot: true, readOnlyRootFilesystem: true }
Why this is correct
This securityContext sets runAsNonRoot to true, which ensures the container does not run as UID 0, and readOnlyRootFilesystem to true, which mounts the root filesystem as read-only. These are the exact settings required to enforce the security policies. They can be applied at the pod or container level, but container-level is more granular.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.