Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A developer wants to ensure a container runs as a non-root user with user ID 1000 and group ID 2000. Which SecurityContext fields should be set?

⚠ Common exam trap

It's easy for candidates to confuse `fsGroup` (which controls group ownership of mounted volumes) with `runAsGroup` (which sets the container process's primary group ID), leading candidates to pick option D instead of B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

runAsUser: 1000, runAsGroup: 2000, runAsNonRoot: true

Setting `runAsUser: 1000` and `runAsGroup: 2000` ensures the container's processes run with user ID 1000 and group ID 2000, while `runAsNonRoot: true` enforces that the container cannot run as root (UID 0), providing a security best practice for non-root execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    runAsUser: 1000, runAsGroup: 2000, runAsNonRoot: false

    Why it's wrong here

    This configuration sets the container's user to UID 1000 and group to GID 2000, but explicitly disables the runAsNonRoot guard by setting it to false. As a result, there is no validation that the effective user is non-root, and if the image's default USER is root or the runAsUser field is later removed, the container could execute as UID 0. Since the developer's goal is to ensure non-root execution, leaving runAsNonRoot false provides no enforcement or security assurance.

  • ✓

    runAsUser: 1000, runAsGroup: 2000, runAsNonRoot: true

    Why this is correct

    This is the correct setup because runAsUser: 1000 forces the container's primary process to execute with UID 1000, and runAsGroup: 2000 sets its primary GID to 2000. The runAsNonRoot: true flag performs a validation at container start, refusing to launch any container whose effective user is UID 0, even if the image's USER directive specifies root. Together these fields completely fulfill the requirement to guarantee non-root execution.

  • ✗

    runAsUser: 1000, runAsGroup: 2000, allowPrivilegeEscalation: false

    Why it's wrong here

    This option omits runAsNonRoot and instead sets allowPrivilegeEscalation: false, which only prevents child processes from gaining additional privileges through mechanisms like setuid binaries. It does not change the container's user: if the image runs as root by default, the primary process will still run as UID 0, just without the ability to escalate privileged operations. Therefore, it does not ensure the container runs as a non-root user and fails the requirement.

  • ✗

    runAsUser: 1000, fsGroup: 2000, runAsNonRoot: true

    Why it's wrong here

    The mistake here is using fsGroup: 2000 instead of runAsGroup: 2000. fsGroup specifies the group ID that owns any mounted volumes and may be used to allow read/write access to those volumes, but it has no effect on the container process's primary GID. Since runAsGroup is absent, the process will inherit the image's user group, so while runAsUser and runAsNonRoot correctly enforce a non-root UID, the group is not set as intended.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.