Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A security requirement states that a container must run with a read-only root filesystem. Which field must be set in the container's securityContext?

⚠ Common exam trap

Many exam-takers confuse security context fields that control process privileges (like `runAsUser` or `capabilities`) with filesystem mount restrictions, mistakenly thinking dropping capabilities or disabling privilege escalation will make the filesystem read-only.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

readOnlyRootFilesystem: true

Setting `readOnlyRootFilesystem: true` in the container's `securityContext` enforces that the container's root filesystem is mounted as read-only, preventing any writes to the filesystem at the root level. This satisfies the security requirement by ensuring that even if a process is compromised, it cannot modify system binaries, configuration files, or other critical files within the container's root filesystem.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    runAsUser: 1000

    Why it's wrong here

    runAsUser: 1000 sets the container process to run as user ID 1000, but this does not affect filesystem write permissions. The root filesystem itself remains writable regardless of the effective user ID. Without readOnlyRootFilesystem: true, the container can still modify its own filesystem, so this does not satisfy the security requirement.

  • ✗

    capabilities: drop: ["ALL"]

    Why it's wrong here

    capabilities: drop: ["ALL"] removes all Linux capabilities from the container's process, which is a good security hardening step. However, it does not make the filesystem read-only; the kernel still allows writes to the filesystem as long as the permissions allow. Since the requirement is that the container must have a read-only root filesystem, this option alone is insufficient.

  • ✗

    allowPrivilegeEscalation: false

    Why it's wrong here

    allowPrivilegeEscalation: false prevents a process from gaining privileges via setuid, setgid, or other mechanisms, but it does not restrict filesystem write operations. The container can still write to its root filesystem because the read-only flag is not set. Therefore, this does not meet the specific security requirement of a read-only root filesystem.

  • ✓

    readOnlyRootFilesystem: true

    Why this is correct

    readOnlyRootFilesystem: true mounts the container's root filesystem as read-only, meaning the container cannot write to any files in its root filesystem. This directly satisfies the security requirement that the container must run with a read-only root filesystem. Any attempt to write to the root filesystem will fail with a read-only file system error.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.