CKAD Practice Question: Application Environment, Configuration and Security
Which of the following is a valid YAML snippet for a container that sets the seccomp profile to 'RuntimeDefault' in a PodSecurityContext?
⚠ Common exam trap
A common mix-up: candidates confuse the `type` key (which specifies the profile type, e.g., RuntimeDefault, Localhost, Unconfined) with a `profile` key, or they flatten the YAML structure by omitting the `seccompProfile` nesting, leading to invalid configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
securityContext: seccompProfile: type: RuntimeDefault
In a PodSecurityContext, the seccomp profile is configured under the `seccompProfile` field with a `type` key set to `RuntimeDefault`. This tells the container runtime (e.g., containerd) to use the default seccomp profile provided by the runtime, which blocks a set of syscalls that are not typically needed by containers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
securityContext: seccompProfile: type: RuntimeDefault
Why this is correct
Correct. In the Pod/container securityContext, seccompProfile is a structured object that selects the seccomp profile applied to the container. Its only required and valid field for this purpose is 'type', and setting type: RuntimeDefault instructs the container runtime (e.g., containerd/Docker) to use the runtime's default seccomp profile, which blocks a defined set of dangerous syscalls while allowing normal operation. This is the correct syntax and is fully supported in Kubernetes v1.19+ when the seccompProfile field is used in the API.
- ✗
securityContext: seccompProfile: profile: RuntimeDefault
Why it's wrong here
Invalid. The seccompProfile object has a field called 'type', not 'profile'. The YAML key 'profile' is not recognized by Kubernetes, so the API would either reject it (strict validation) or ignore it, leaving the container without a seccomp profile. The correct way to specify RuntimeDefault is type: RuntimeDefault. Confusing 'type' with 'profile' is a common typo because older alpha-style annotations used 'profile', but current stable API uses 'type'.
- ✗
securityContext: seccomp: RuntimeDefault
Why it's wrong here
Invalid. Kubernetes does not support a 'seccomp' field directly under securityContext. The correct parent field is 'seccompProfile', which is a nested object. Writing seccomp: RuntimeDefault would be silently ignored or cause a validation error, meaning no seccomp profile is applied. The container would run without the requested confinement, defeating the purpose of the setting.
- ✗
securityContext: seccomp: type: RuntimeDefault
Why it's wrong here
Invalid. This combines two errors: the top-level field is 'seccompProfile' (not 'seccomp'), and the nested field is 'type' (not 'profile'). The correct syntax is securityContext: seccompProfile: type: RuntimeDefault. Because 'seccomp' is not a recognized field, Kubernetes ignores it entirely, so even though 'type' is the right subfield name, it's under a wrong parent, and no seccomp profile is actually applied.
Go deeper
Related to this question
About these practice questions
This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.