CKAD Practice Question: Application Environment, Configuration and Security
A pod is failing to start with error 'container has runAsNonRoot and image will run as root'. The container image runs as root. Which change allows the pod to run?
⚠ Common exam trap
The trap here is that candidates mistakenly think removing runAsNonRoot (Option A) is the fix, but the exam tests that you must satisfy the security constraint by changing the user, not disabling the check.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set runAsUser to a non-zero UID, e.g., 1000
The error 'container has runAsNonRoot and image will run as root' indicates that the pod's securityContext has runAsNonRoot: true, but the container image runs as root (UID 0). To satisfy the runAsNonRoot constraint, you must override the container's user to a non-zero UID by setting runAsUser to a non-zero value (e.g., 1000). This forces the container to run as a non-root user, resolving the conflict.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove runAsNonRoot: true from securityContext
Why it's wrong here
Deleting runAsNonRoot: true from the securityContext does not change the container's runtime user; it only removes the admission-time validation that prevents the container from starting. If the image naturally runs as UID 0 (root), the pod will still attempt to start as root, and while it may pass the Kubernetes admission check, it would violate the cluster's Pod Security Standards or fail later if the container runtime enforces a read-only root filesystem or other restrictions. Moreover, the error 'container has runAsNonRoot' specifically signals that the container image declares a USER that is root, or no USER at all, and the safeguard was blocking it—removing the safeguard is the opposite of the intended fix.
- ✗
Add fsGroup: 1000
Why it's wrong here
Adding fsGroup: 1000 to the pod's securityContext changes the group ownership of any mounted volumes (e.g., PersistentVolumeClaims, ConfigMaps) to GID 1000, and the effective group ID of the container process is set to that GID. It does not alter the UID (user ID) with which the container's main process runs; the process remains whatever user was set by the image or by runAsUser. The runAsNonRoot check only inspects the effective user ID—not the group ID—so fsGroup cannot satisfy the requirement that the container run as a non-root user.
- ✗
Set allowPrivilegeEscalation: false
Why it's wrong here
Setting allowPrivilegeEscalation: false only prevents the container process from gaining more privileges than its parent process, such as through setuid binaries or the no_new_privs Linux capability. It has no effect on the initial UID of the container process: if the image runs as UID 0, the container will still start as root, and the runAsNonRoot check will still fail. This option is useful for hardening a container after you have already set a non-root UID, but it is not a substitute for actually running as a non-root user.
- ✓
Set runAsUser to a non-zero UID, e.g., 1000
Why this is correct
Setting runAsUser to a non-zero UID (e.g., 1000) explicitly overrides the user ID with which the container's main process runs. When runAsNonRoot: true is set, Kubernetes admission (and the container runtime) verifies that the resulting effective UID is non-zero, so a UID of 1000 satisfies the check. This is the correct fix because it keeps the security safeguard while ensuring the container actually runs as a non-root user, avoiding the immediate error and complying with best practices for container security.
Visual reference
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.