CKAD Practice Question: Application Environment, Configuration and Security
A pod needs to run as a non-root user. Which securityContext field should be set to enforce this?
⚠ Common exam trap
Watch out — candidates often confuse `runAsUser: 1000` with enforcing non-root execution, but it only sets a user ID and does not prevent the container from running as root if the image's entrypoint ignores the UID setting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
runAsNonRoot: true
Setting `runAsNonRoot: true` in the pod's securityContext explicitly enforces that the container must not run as the root user (UID 0). If the container image attempts to run as root, the Pod will fail to start, ensuring compliance with non-root security policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
runAsGroup: 3000
Why it's wrong here
runAsGroup: 3000 sets the supplemental group ID for the container's primary process, but it does not alter the user ID (UID). A container can still execute with UID 0 (root) while having a non-root group, so this field alone fails to satisfy the requirement that the pod run as a non-root user. Group ownership is orthogonal to user privilege, and a root user can still access files based on group permissions, meaning this setting provides no guarantee of a non-root identity.
- ✗
runAsUser: 1000
Why it's wrong here
runAsUser: 1000 specifies the default UID that the container's entrypoint should use, but it is not an enforcement mechanism. If the container image includes a directive to switch back to root—such as an entrypoint that invokes 'su' or 'gosu'—the process can still elevate to UID 0. Also, Kubernetes only applies this value to the main container process, and any process it spawns may inherit a different effective UID if the image logic changes it. Thus, runAsUser merely suggests a non-root identity rather than guaranteeing one, and a malicious or misconfigured image can still run as root.
- ✗
readOnlyRootFilesystem: true
Why it's wrong here
readOnlyRootFilesystem: true mounts the container's root filesystem as read-only, which restricts write access to filesystem paths but does not constrain the user's identity. The container process can still run as root (UID 0) and simply lacks write access to the root filesystem. While this is a useful defense-in-depth measure to limit the impact of a compromise, it does not address the requirement that the pod explicitly run as a non-root user. It is about filesystem immutability, not user privilege.
- ✓
runAsNonRoot: true
Why this is correct
runAsNonRoot: true is a securityContext validation that ensures the container will not start if it is configured to run as root. Kubernetes checks the user defined in the image metadata (or the runtime user) and refuses to launch the pod if the UID is 0 or unspecified. This directly enforces the non-root requirement, providing a hard guarantee that the container runs with an unprivileged user ID. It is the only option that actively prevents root execution, making it the correct choice for this question.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.