Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

To prevent a container from running as root, which field should be set in the securityContext?

⚠ Common exam trap

Test-takers frequently confuse `runAsNonRoot: true` with `runAsUser: 1000`, mistakenly thinking that setting a non-zero user ID alone guarantees the container does not run as root, when in fact `runAsUser` only sets the UID and does not enforce a root check, leaving the container vulnerable if the image defaults to root.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

runAsNonRoot: true

The `runAsNonRoot: true` field in the securityContext explicitly prevents the container from running as the root user (UID 0). When set, Kubernetes will refuse to start the container if the image is configured to run as root, enforcing a non-root execution policy at the pod or container level. This is the direct and intended mechanism for ensuring the container does not run with root privileges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    runAsUser: 1000

    Why it's wrong here

    Setting runAsUser: 1000 explicitly assigns the container's UID to 1000, which overrides the image's default user. However, this merely specifies a user ID; it does not enforce a policy that the container must not run as root. The container could still be started with a different image or an override that sets the user back to 0 (root), and runAsUser itself does not validate or enforce non-root execution at the admission or runtime level.

  • ✓

    runAsNonRoot: true

    Why this is correct

    runAsNonRoot: true is the correct field because it actively enforces a security requirement that the container must not run as root. When set, the kubelet checks the user the image would run as: if that user is root (UID 0) or the image does not define a non-root user, the container is not started and the Pod fails. This provides a strong guarantee that the container process never executes with root privileges, regardless of the image's default configuration.

  • ✗

    allowPrivilegeEscalation: false

    Why it's wrong here

    allowPrivilegeEscalation: false disables mechanisms like setuid or setgid binaries that can raise the process's privileges after startup. But this setting does not prevent the container from initially running as root; it only blocks privilege escalation from a non-root user to a higher privilege. If the image starts with UID 0, the container will still be rooted, so this alone does not satisfy the 'must not run as root' requirement.

  • ✗

    readOnlyRootFilesystem: true

    Why it's wrong here

    readOnlyRootFilesystem: true mounts the container's root filesystem as read-only, preventing writes to most system paths. This is a useful hardening measure against tampering, but it has no effect on the user ID under which the process runs. The container could still run as root and have full privileges over read-only files, so it is not a substitute for runAsNonRoot.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.