Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A container image requires a seccomp profile that is not the default. The cluster supports the RuntimeDefault seccomp profile. Which Pod securityContext field should be configured to use the RuntimeDefault seccomp profile?

⚠ Common exam trap

It's easy for candidates to confuse the old alpha annotation `seccomp.security.alpha.kubernetes.io/pod` (deprecated in 1.19) with the current `seccompProfile` field, or they mistakenly think `capabilities` can set the seccomp profile, when in fact capabilities only grant permission to use seccomp syscalls, not apply a profile.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

seccompProfile: type: RuntimeDefault

The `seccompProfile` field under the Pod's `securityContext` is the proper way to specify a seccomp profile in Kubernetes. Setting `type: RuntimeDefault` tells the container runtime (e.g., containerd or CRI-O) to use the default seccomp profile provided by the runtime, which is a secure baseline that blocks around 44 system calls while allowing common ones like `read`, `write`, and `exit`. This field was introduced in Kubernetes 1.19 (GA in 1.22) and is the standard approach for configuring seccomp at the Pod or container level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    seccompProfile: type: RuntimeDefault

    Why this is correct

    The correct configuration under a container's securityContext is seccompProfile, and setting its type to RuntimeDefault tells the container runtime to apply its built-in default seccomp profile. This profile restrictively filters syscalls, blocking dangerous ones while allowing normal operation, without requiring you to ship a custom profile. It is the preferred way to enable seccomp in modern Kubernetes because it delegates the policy to the runtime, which is already tuned for safe defaults.

  • ✗

    seccomp: type: RuntimeDefault

    Why it's wrong here

    This option uses the wrong field name. In the Pod and container securityContext, the field is seccompProfile, not seccomp. Using 'seccomp' causes a schema validation error and the manifest will be rejected by the API server. Even though the intention is correct, the misspelled key prevents the seccompProfile settings from being applied, so the container would not get the RuntimeDefault profile.

  • ✗

    capabilities: add: [SECCOMP]

    Why it's wrong here

    There is no Linux capability called SECCOMP. Capabilities are discrete privileges like CAP_NET_ADMIN or CAP_SYS_TIME, and they are configured via the capabilities.add field. Seccomp is a separate kernel security feature that filters system calls, and it is configured exclusively through seccompProfile, not through capabilities. Adding 'SECCOMP' to capabilities either causes an error or, if accepted by the runtime, has no effect on seccomp filtering, so it is an invalid and ineffective approach.

  • ✗

    securityContext: seccomp: type: Unconfined

    Why it's wrong here

    This option incorrectly nests the seccomp key directly under securityContext and uses the value Unconfined. The correct field name is seccompProfile, so this would be ignored or rejected. Even if it were named correctly, setting type to Unconfined explicitly disables seccomp, leaving the container with no syscall filtering—the opposite of the required protection. The desired behavior is to enable the runtime's default profile, so both the field name and the value are wrong.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.