CKAD Practice Question: Application Environment, Configuration and Security
A security requirement states that a container must run with a read-only root filesystem. Which field must be set in the container's securityContext?
⚠ Common exam trap
Many exam-takers confuse security context fields that control process privileges (like `runAsUser` or `capabilities`) with filesystem mount restrictions, mistakenly thinking dropping capabilities or disabling privilege escalation will make the filesystem read-only.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
readOnlyRootFilesystem: true
Setting `readOnlyRootFilesystem: true` in the container's `securityContext` enforces that the container's root filesystem is mounted as read-only, preventing any writes to the filesystem at the root level. This satisfies the security requirement by ensuring that even if a process is compromised, it cannot modify system binaries, configuration files, or other critical files within the container's root filesystem.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
runAsUser: 1000
Why it's wrong here
runAsUser: 1000 sets the container process to run as user ID 1000, but this does not affect filesystem write permissions. The root filesystem itself remains writable regardless of the effective user ID. Without readOnlyRootFilesystem: true, the container can still modify its own filesystem, so this does not satisfy the security requirement.
- ✗
capabilities: drop: ["ALL"]
Why it's wrong here
capabilities: drop: ["ALL"] removes all Linux capabilities from the container's process, which is a good security hardening step. However, it does not make the filesystem read-only; the kernel still allows writes to the filesystem as long as the permissions allow. Since the requirement is that the container must have a read-only root filesystem, this option alone is insufficient.
- ✗
allowPrivilegeEscalation: false
Why it's wrong here
allowPrivilegeEscalation: false prevents a process from gaining privileges via setuid, setgid, or other mechanisms, but it does not restrict filesystem write operations. The container can still write to its root filesystem because the read-only flag is not set. Therefore, this does not meet the specific security requirement of a read-only root filesystem.
- ✓
readOnlyRootFilesystem: true
Why this is correct
readOnlyRootFilesystem: true mounts the container's root filesystem as read-only, meaning the container cannot write to any files in its root filesystem. This directly satisfies the security requirement that the container must run with a read-only root filesystem. Any attempt to write to the root filesystem will fail with a read-only file system error.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.