Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A security requirement states: 'The container must drop all capabilities and add only NET_BIND_SERVICE'. Which YAML snippet correctly implements this in the securityContext?

⚠ Common exam trap

Many candidates confuse the order of `add` and `drop`, or mistakenly think that dropping `ALL` includes the capability they want to add, leading them to pick options that either drop the needed capability or add too many.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

securityContext: capabilities: drop: [ALL] add: ["NET_BIND_SERVICE"]

It first drops all capabilities with `drop: [ALL]` and then explicitly adds only `NET_BIND_SERVICE` via `add: ["NET_BIND_SERVICE"]`. This matches the security requirement exactly: the container starts with no capabilities and gains only the one needed to bind to privileged ports (<1024). In Kubernetes, the order of `drop` and `add` matters — dropping ALL first ensures a clean slate, then adding the specific capability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    securityContext: capabilities: drop: ["NET_BIND_SERVICE"] add: [ALL]

    Why it's wrong here

    This configuration attempts to drop only NET_BIND_SERVICE while adding ALL, which grants every Linux capability to the container. Adding ALL supersedes the single drop entry because NET_BIND_SERVICE is included in the ALL set, leaving the container with a fully privileged capability set. That directly violates the security requirement to drop all capabilities and is a common anti-pattern that provides blanket root-level access.

  • ✓

    securityContext: capabilities: drop: [ALL] add: ["NET_BIND_SERVICE"]

    Why this is correct

    This is correct because drop: [ALL] first removes every capability from the container's effective and bounding sets, and add: ["NET_BIND_SERVICE"] then explicitly grants only the one capability required for binding to privileged ports such as 80 and 443. The resulting container runs with the minimal capability set possible, adhering to the principle of least privilege and satisfying the security requirement.

  • ✗

    securityContext: capabilities: add: [ALL] drop: ["NET_BIND_SERVICE"]

    Why it's wrong here

    This is the inverse of the correct configuration: add: [ALL] grants the container every capability, and drop: ["NET_BIND_SERVICE"] removes only that single capability. The container remains privileged with broad access to kernel operations, which is the opposite of the requirement to drop all capabilities, and it would still not allow binding to low-numbered ports because that capability was dropped.

  • ✗

    securityContext: capabilities: "drop ALL; add NET_BIND_SERVICE"

    Why it's wrong here

    The capabilities field must be a structured object with add and drop arrays, not a string. Supplying a value like "drop ALL; add NET_BIND_SERVICE" is invalid against the Kubernetes API schema, so the Pod will be rejected with a validation error and never scheduled. Even if a runtime attempted to interpret it, the semantics would be ambiguous and non-standard, so this cannot satisfy the security requirement.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.