Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A developer wants to run a container as a non-root user and prevent it from gaining additional privileges. The container image runs as root by default. Which securityContext configuration should be applied to the container to achieve this?

⚠ Common exam trap

The trap here is thinking that runAsNonRoot alone is sufficient, or that privileged: false prevents privilege escalation, when actually allowPrivilegeEscalation is the specific control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

securityContext: { runAsUser: 1000, allowPrivilegeEscalation: false }

To run as a non-root user, runAsUser must be set to a non-zero UID. To prevent privilege escalation, allowPrivilegeEscalation must be false. The combination of runAsUser: 1000 and allowPrivilegeEscalation: false achieves both goals. Other options either fail to set a non-root user, enable privilege escalation, or rely on runAsNonRoot without specifying a UID.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    securityContext: { runAsUser: 1000, privileged: true }

    Why it's wrong here

    While runAsUser: 1000 sets a non-root user, privileged: true gives the container almost all capabilities of the host, which is the opposite of preventing privilege escalation. This configuration would allow the container to gain extensive privileges, violating the requirement.

  • ✗

    securityContext: { runAsGroup: 1000, allowPrivilegeEscalation: true }

    Why it's wrong here

    Setting runAsGroup: 1000 only sets the primary group ID, not the user ID. The container could still run as root. allowPrivilegeEscalation: true explicitly permits privilege escalation, which is contrary to the goal. This configuration does not meet the requirement.

  • ✗

    securityContext: { runAsNonRoot: true, privileged: false }

    Why it's wrong here

    runAsNonRoot: true ensures the container does not run as root, but it requires that the image specifies a non-root user or that runAsUser is also set. privileged: false is the default and does not specifically prevent privilege escalation. This combination does not guarantee a non-root UID if the image's default user is root and no runAsUser is provided; the container would fail to start.

  • ✓

    securityContext: { runAsUser: 1000, allowPrivilegeEscalation: false }

    Why this is correct

    Setting runAsUser: 1000 ensures the container process runs as a non-root user. allowPrivilegeEscalation: false prevents the process from gaining more privileges than its parent (e.g., via setuid or setgid binaries). Together, these satisfy the requirements. This is a common best practice for hardening container security.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.