CKAD Practice Question: Application Environment, Configuration and Security
To prevent a container from running as root, which field should be set in the securityContext?
⚠ Common exam trap
Test-takers frequently confuse `runAsNonRoot: true` with `runAsUser: 1000`, mistakenly thinking that setting a non-zero user ID alone guarantees the container does not run as root, when in fact `runAsUser` only sets the UID and does not enforce a root check, leaving the container vulnerable if the image defaults to root.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
runAsNonRoot: true
The `runAsNonRoot: true` field in the securityContext explicitly prevents the container from running as the root user (UID 0). When set, Kubernetes will refuse to start the container if the image is configured to run as root, enforcing a non-root execution policy at the pod or container level. This is the direct and intended mechanism for ensuring the container does not run with root privileges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
runAsUser: 1000
Why it's wrong here
Setting runAsUser: 1000 explicitly assigns the container's UID to 1000, which overrides the image's default user. However, this merely specifies a user ID; it does not enforce a policy that the container must not run as root. The container could still be started with a different image or an override that sets the user back to 0 (root), and runAsUser itself does not validate or enforce non-root execution at the admission or runtime level.
- ✓
runAsNonRoot: true
Why this is correct
runAsNonRoot: true is the correct field because it actively enforces a security requirement that the container must not run as root. When set, the kubelet checks the user the image would run as: if that user is root (UID 0) or the image does not define a non-root user, the container is not started and the Pod fails. This provides a strong guarantee that the container process never executes with root privileges, regardless of the image's default configuration.
- ✗
allowPrivilegeEscalation: false
Why it's wrong here
allowPrivilegeEscalation: false disables mechanisms like setuid or setgid binaries that can raise the process's privileges after startup. But this setting does not prevent the container from initially running as root; it only blocks privilege escalation from a non-root user to a higher privilege. If the image starts with UID 0, the container will still be rooted, so this alone does not satisfy the 'must not run as root' requirement.
- ✗
readOnlyRootFilesystem: true
Why it's wrong here
readOnlyRootFilesystem: true mounts the container's root filesystem as read-only, preventing writes to most system paths. This is a useful hardening measure against tampering, but it has no effect on the user ID under which the process runs. The container could still run as root and have full privileges over read-only files, so it is not a substitute for runAsNonRoot.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.