CKAD Practice Question: Application Environment, Configuration and Security
A cluster administrator wants to prevent all pods in a namespace from running with privileged escalation. Which Pod Security Admission standard enforces this?
⚠ Common exam trap
CNCF often tests the distinction between 'baseline' and 'restricted' standards, where candidates mistakenly choose 'baseline' because it blocks some privilege escalation but fails to recognize that 'restricted' is the only standard that explicitly and comprehensively prohibits `AllowPrivilegeEscalation`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
restricted
The 'restricted' Pod Security Admission (PSA) standard enforces the most stringent security controls, including preventing privileged escalation by setting `securityContext.AllowPrivilegeEscalation` to `false` and requiring containers to run as non-root. This directly addresses the cluster administrator's goal of blocking privilege escalation in all pods within a namespace.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
baseline
Why it's wrong here
The baseline Pod Security Standard is designed to prevent known privilege escalations, but it only bans the most obvious violations such as privileged containers and host namespaces. It stops short of the restricted profile by allowing containers to run as root, retain all capabilities, and omit seccomp settings. Because the requirement is to prevent all pods from allowing privilege escalation, baseline's permissive exceptions leave that critical control unenforced.
- ✓
restricted
Why this is correct
The restricted Pod Security Standard is the only built-in profile that explicitly mandates `allowPrivilegeEscalation: false` for all containers, effectively closing the door on any capability-based privilege escalation. It also requires a seccomp profile of RuntimeDefault, dropping all capabilities, and running as a non-root user, which collectively harden the container against breakout. By labeling the namespace with `pod-security.kubernetes.io/enforce=restricted`, the Pod Security Admission controller rejects any pod that violates these constraints, ensuring every pod in the namespace meets this strict baseline.
- ✗
privileged
Why it's wrong here
The privileged profile serves as an unrestricted policy that grants pods the exact same access as the host, permitting privileged containers, host namespaces, and full privilege escalation. Under this profile, securityContext fields such as `allowPrivilegeEscalation: true` and `privileged: true` are accepted without any validation, making it impossible to block escalation. Choosing this profile would directly contradict the administrator's goal, as it actively allows the dangerous behavior they need to prevent.
- ✗
high
Why it's wrong here
Kubernetes Pod Security Standards do not include a profile named 'high'; the three recognized levels are privileged, baseline, and restricted. Since Pod Security Admission only enforces these predefined standards, setting a namespace to 'high' would have no effect and likely cause a configuration error. Without a valid enforcement level, the admission controller cannot apply any restrictions, so privilege escalation would remain possible in all pods.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.