Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A pod needs to run as a non-root user. Which securityContext field should be set to enforce this?

⚠ Common exam trap

Watch out — candidates often confuse `runAsUser: 1000` with enforcing non-root execution, but it only sets a user ID and does not prevent the container from running as root if the image's entrypoint ignores the UID setting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

runAsNonRoot: true

Setting `runAsNonRoot: true` in the pod's securityContext explicitly enforces that the container must not run as the root user (UID 0). If the container image attempts to run as root, the Pod will fail to start, ensuring compliance with non-root security policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    runAsGroup: 3000

    Why it's wrong here

    runAsGroup: 3000 sets the supplemental group ID for the container's primary process, but it does not alter the user ID (UID). A container can still execute with UID 0 (root) while having a non-root group, so this field alone fails to satisfy the requirement that the pod run as a non-root user. Group ownership is orthogonal to user privilege, and a root user can still access files based on group permissions, meaning this setting provides no guarantee of a non-root identity.

  • ✗

    runAsUser: 1000

    Why it's wrong here

    runAsUser: 1000 specifies the default UID that the container's entrypoint should use, but it is not an enforcement mechanism. If the container image includes a directive to switch back to root—such as an entrypoint that invokes 'su' or 'gosu'—the process can still elevate to UID 0. Also, Kubernetes only applies this value to the main container process, and any process it spawns may inherit a different effective UID if the image logic changes it. Thus, runAsUser merely suggests a non-root identity rather than guaranteeing one, and a malicious or misconfigured image can still run as root.

  • ✗

    readOnlyRootFilesystem: true

    Why it's wrong here

    readOnlyRootFilesystem: true mounts the container's root filesystem as read-only, which restricts write access to filesystem paths but does not constrain the user's identity. The container process can still run as root (UID 0) and simply lacks write access to the root filesystem. While this is a useful defense-in-depth measure to limit the impact of a compromise, it does not address the requirement that the pod explicitly run as a non-root user. It is about filesystem immutability, not user privilege.

  • ✓

    runAsNonRoot: true

    Why this is correct

    runAsNonRoot: true is a securityContext validation that ensures the container will not start if it is configured to run as root. Kubernetes checks the user defined in the image metadata (or the runtime user) and refuses to launch the pod if the UID is 0 or unspecified. This directly enforces the non-root requirement, providing a hard guarantee that the container runs with an unprivileged user ID. It is the only option that actively prevents root execution, making it the correct choice for this question.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.