Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A pod is configured with 'securityContext.seccompProfile.type: RuntimeDefault' but the container still attempts to use a syscall that is blocked by the default seccomp profile. What happens?

⚠ Common exam trap

Watch out — candidates often assume any security violation immediately kills the container or evicts the pod, but seccomp violations only fail the specific syscall, and the container may continue if the process handles the error.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The syscall fails with an error, but the container may continue running.

When a container uses a syscall blocked by the seccomp profile, the syscall itself fails (returns an error like EPERM or is killed by SIGSYS), but the container process can handle that error and continue running. The `RuntimeDefault` profile applies Docker's default seccomp profile, which blocks around 44 syscalls (e.g., `mount`, `ptrace`, `perf_event_open`), but does not terminate the container unless the process exits due to the failed syscall. The container is not killed by Kubernetes; only the specific syscall is denied by the kernel's seccomp mechanism.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The container is killed because it violated the seccomp policy.

    Why it's wrong here

    A seccomp violation does not cause the container to be killed. Seccomp works by intercepting system calls and returning an error (typically EPERM) to the calling process, rather than sending a signal or terminating the process. The process remains alive; it may crash only if the application does not handle the returned error gracefully. Neither the container runtime nor the kubelet takes action to kill a container solely because a syscall was blocked by a seccomp profile.

  • ✗

    The pod is evicted by the kubelet because of a security violation.

    Why it's wrong here

    Pod eviction by the kubelet is triggered by node-level conditions such as memory pressure, disk pressure, or node unreachability, not by security policy violations. A seccomp violation is an application-level syscall error that occurs inside the container's kernel context; the kubelet is not even aware that a syscall was blocked. Therefore, the pod is not evicted and continues to run unless the application itself exits due to the error.

  • ✗

    The container runs successfully because RuntimeDefault allows all syscalls.

    Why it's wrong here

    The RuntimeDefault seccomp profile, which is typically the containerd or Docker default, is not permissive of all syscalls. It explicitly blocks a set of dangerous or unnecessary syscalls, including mount, reboot, kexec_load, and others that could affect the host or violate the container's isolation. Consequently, a container using RuntimeDefault will fail syscalls that are on the blocklist, even though it permits most common syscalls like read, write, and open.

  • ✓

    The syscall fails with an error, but the container may continue running.

    Why this is correct

    When a syscall is blocked by a seccomp profile, the kernel returns an error (commonly EPERM) to the process that made the call. The process's behavior after that depends entirely on how the application handles the error: it may log the failure, retry, or abort, but the container itself is not automatically stopped. Many applications do not check for seccomp-related errors and continue running with degraded functionality, so the container often remains alive and running.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.