CKAD Practice Question: Application Environment, Configuration and Security
A Pod is configured with a securityContext that sets runAsUser: 1000 and runAsGroup: 3000 at the pod level. A container within that Pod has its own securityContext that sets runAsUser: 2000 but does not set runAsGroup. The container process attempts to create a file in a directory owned by group 3000 with group write permissions. Which two statements are true regarding the effective user and group of the container process? (Choose two.)
⚠ Common exam trap
The trap here is assuming that setting runAsUser at the container level also changes the group, or that pod-level settings override container-level settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The container process runs with UID 2000.
Container-level securityContext overrides pod-level for the same field, so runAsUser: 2000 applies. For runAsGroup, the container does not specify it, so it inherits the pod-level runAsGroup: 3000. Thus the process runs as UID 2000 and GID 3000, allowing write access to the group-writable directory.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The container process runs with UID 1000 because pod-level settings take precedence.
Why it's wrong here
Pod-level securityContext settings are defaults that can be overridden by container-level settings. The container explicitly sets runAsUser: 2000, which takes precedence over the pod-level runAsUser: 1000. Therefore, the process runs as UID 2000, not 1000. This option incorrectly assumes pod-level settings always win.
- ✓
The container process runs with UID 2000.
Why this is correct
The container-level securityContext overrides the pod-level setting for runAsUser. Since the container specifies runAsUser: 2000, the process inside that container will run as UID 2000. This is a fundamental principle of securityContext inheritance: more specific scopes override broader ones. The pod-level runAsUser: 1000 is superseded for this container.
- ✓
The container process runs with GID 3000.
Why this is correct
The container-level securityContext does not specify runAsGroup, so it inherits the pod-level runAsGroup: 3000. Therefore, the primary group ID of the container process is 3000. This allows the process to write to directories owned by group 3000 with group write permissions, assuming no other restrictions apply.
- ✗
The container process runs with GID 2000 because the container's runAsUser implies a matching group.
Why it's wrong here
There is no automatic mapping from runAsUser to runAsGroup. The group ID is determined solely by the runAsGroup setting, which is inherited from the pod level as 3000. The container's runAsUser: 2000 does not affect the group ID. This option confuses user and group settings.
- ✗
The container process cannot write to the directory because the group ID does not match the directory's group owner.
Why it's wrong here
The container process has GID 3000, which matches the directory's group owner, and the directory has group write permissions. Therefore, the process can write to the directory, provided no other security controls prevent it. This option incorrectly assumes a mismatch or ignores the inherited group ID.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.