CKAD Practice Question: Application Environment, Configuration and Security
A pod is running with a SecurityContext that sets 'runAsUser: 1000' and 'runAsGroup: 3000'. The container process is running as user 1000. However, the container needs to access a file on a mounted volume that is owned by user 1000 and group 2000. Which SecurityContext setting should be added to ensure the container can read the file?
⚠ Common exam trap
CKAD often tests the confusion between runAsGroup (the process's primary GID) and fsGroup (the volume's group ownership), leading candidates to pick runAsGroup when the real issue is on-disk file group ownership.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set fsGroup: 2000 in the pod-level securityContext
fsGroup is a pod-level SecurityContext setting that causes Kubernetes to recursively change the group ownership of the volume's files to the specified GID and adds the container's supplemental group list. Setting fsGroup: 2000 makes the mounted volume files group-owned by GID 2000, and the container process running as user 1000 inherits 2000 as a supplemental group, granting read access. This is the canonical fix when a volume's group ownership does not match the container's primary runAsGroup.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set fsGroup: 2000 in the pod-level securityContext
Why this is correct
Set fsGroup: 2000 in the pod-level securityContext - This ensures the volume files' group ownership is changed to 2000 and the container process is part of that supplementary group, allowing read access. This is the correct approach.
- ✗
Set readOnlyRootFilesystem: true
Why it's wrong here
Setting readOnlyRootFilesystem: true only mounts the container's own root filesystem as read-only inside the container. It has no effect on mounted volumes (such as PersistentVolumes or ConfigMaps) and does not alter file ownership or permissions anywhere. Even with a read-only rootfs, the process can still be denied read access to a volume if the volume's Unix permissions do not allow the user or group of the process to read the files. This option changes the filesystem's writeability, not the access-control metadata relevant to the scenario.
- ✗
Set runAsGroup: 2000
Why it's wrong here
Set runAsGroup: 2000 - Changing the primary group of the process to 2000 does not address volume permissions because the file's group is already 2000 and the process is already user 1000 (the owner). However, without fsGroup, the volume may not have the correct group ownership, so this option is not sufficient.
- ✗
Add capability: CAP_DAC_READ_SEARCH
Why it's wrong here
Adding CAP_DAC_READ_SEARCH grants a process the Linux capability to bypass discretionary access control (DAC) checks, meaning it can read files and search directories regardless of the file's mode bits. While this would technically allow the process to read the volume files even if the user/group lacks permissions, it is a heavy-handed, privileged capability that is not the intended Kubernetes mechanism for granting regular file access. The recommended, least-privilege approach is to use fsGroup in the pod's securityContext, which adjusts the group ownership of the mounted volume and adds the group to the process's supplementary groups. Using a raw capability also has security implications and is unnecessarily broad for this simple use case.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.