CKAD Practice Question: Application Environment, Configuration and Security
A pod has securityContext with capabilities.add: ['NET_ADMIN'] and capabilities.drop: ['ALL']. What effective capabilities does the container have?
⚠ Common exam trap
The trap here is that candidates mistakenly think `drop: ['ALL']` overrides any `add` directives, or that the order of `drop` and `add` in the YAML matters, when in fact Kubernetes always processes `drop` first regardless of the order they are listed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Only NET_ADMIN
When a container's securityContext specifies both `capabilities.drop: ['ALL']` and `capabilities.add: ['NET_ADMIN']`, the `drop: ['ALL']` first removes all capabilities, and then `add: ['NET_ADMIN']` adds back only the NET_ADMIN capability. The final effective set is exactly `[NET_ADMIN]`. This is the intended Kubernetes behavior: `drop` is processed before `add` within the same container spec.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
No capabilities
Why it's wrong here
This is incorrect because a pod that drops ALL capabilities and then adds NET_ADMIN does not end up with an empty capability set. The container runtime processes the drop list first, removing every inherited and default capability, then applies the add list, which grants NET_ADMIN back. Since NET_ADMIN is explicitly re-added after the drop, the process has that capability available in its effective, permitted, and bounding sets. Thus, saying 'No capabilities' ignores that a later add intentionally reintroduces one specific privilege.
- ✗
All capabilities
Why it's wrong here
This is incorrect because dropping ALL does more than remove the default capabilities; it erases every capability that might have been present before the drop, including anything that was added via an add list. If the securityContext only adds NET_ADMIN after the drop, the final capability set is exactly NET_ADMIN, not a full set. Since the drop-to-ALL step acts as a reset and the add step is selective, there is no mechanism by which all Linux capabilities would be present. Therefore, 'All capabilities' overstates what the runtime grants after the ordered drop-then-add processing.
- ✓
Only NET_ADMIN
Why this is correct
This is correct. When a securityContext capabilities block contains drop: ["ALL"] and add: ["NET_ADMIN"], the container runtime first removes all capabilities from the container's default capability perimeter, then applies the add list to grant only NET_ADMIN. The result is a capability set with a single entry: CAP_NET_ADMIN, which permits privileged network operations such as interface configuration and firewall changes. All other capabilities, including common defaults like CHOWN or DAC_OVERRIDE, remain dropped because the drop ALL operation preceded the add. This narrow, explicit grant is often a deliberate least-privilege pattern, but it should be paired with a recognized need for network administration only.
- ✗
All capabilities except NET_ADMIN
Why it's wrong here
This is incorrect because the drop ALL operation removes the entire inherited default capability set, so no other capabilities survive to remain alongside NET_ADMIN. The add operation then introduces NET_ADMIN as the sole exception to the empty set. Someone choosing 'All capabilities except NET_ADMIN' likely assumes the default capabilities are untouched and only NET_ADMIN is missing, but that is the opposite of the actual behavior. In reality, drop ALL empties the set, and the one explicit add is the only capability present, so every capability except NET_ADMIN is absent, not present.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.