Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which of the following is a valid YAML snippet for a container that sets the seccomp profile to 'RuntimeDefault' in a PodSecurityContext?

⚠ Common exam trap

A common mix-up: candidates confuse the `type` key (which specifies the profile type, e.g., RuntimeDefault, Localhost, Unconfined) with a `profile` key, or they flatten the YAML structure by omitting the `seccompProfile` nesting, leading to invalid configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

securityContext: seccompProfile: type: RuntimeDefault

In a PodSecurityContext, the seccomp profile is configured under the `seccompProfile` field with a `type` key set to `RuntimeDefault`. This tells the container runtime (e.g., containerd) to use the default seccomp profile provided by the runtime, which blocks a set of syscalls that are not typically needed by containers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    securityContext: seccompProfile: type: RuntimeDefault

    Why this is correct

    Correct. In the Pod/container securityContext, seccompProfile is a structured object that selects the seccomp profile applied to the container. Its only required and valid field for this purpose is 'type', and setting type: RuntimeDefault instructs the container runtime (e.g., containerd/Docker) to use the runtime's default seccomp profile, which blocks a defined set of dangerous syscalls while allowing normal operation. This is the correct syntax and is fully supported in Kubernetes v1.19+ when the seccompProfile field is used in the API.

  • ✗

    securityContext: seccompProfile: profile: RuntimeDefault

    Why it's wrong here

    Invalid. The seccompProfile object has a field called 'type', not 'profile'. The YAML key 'profile' is not recognized by Kubernetes, so the API would either reject it (strict validation) or ignore it, leaving the container without a seccomp profile. The correct way to specify RuntimeDefault is type: RuntimeDefault. Confusing 'type' with 'profile' is a common typo because older alpha-style annotations used 'profile', but current stable API uses 'type'.

  • ✗

    securityContext: seccomp: RuntimeDefault

    Why it's wrong here

    Invalid. Kubernetes does not support a 'seccomp' field directly under securityContext. The correct parent field is 'seccompProfile', which is a nested object. Writing seccomp: RuntimeDefault would be silently ignored or cause a validation error, meaning no seccomp profile is applied. The container would run without the requested confinement, defeating the purpose of the setting.

  • ✗

    securityContext: seccomp: type: RuntimeDefault

    Why it's wrong here

    Invalid. This combines two errors: the top-level field is 'seccompProfile' (not 'seccomp'), and the nested field is 'type' (not 'profile'). The correct syntax is securityContext: seccompProfile: type: RuntimeDefault. Because 'seccomp' is not a recognized field, Kubernetes ignores it entirely, so even though 'type' is the right subfield name, it's under a wrong parent, and no seccomp profile is actually applied.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.