Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which THREE of the following are capabilities that can be added to a container's securityContext?

⚠ Common exam trap

Candidates often confuse seccomp profiles (like RuntimeDefault) with Linux capabilities, or they assume that all capability names must be prefixed with 'CAP_' in the YAML (e.g., writing 'CAP_NET_ADMIN' instead of 'NET_ADMIN'), leading them to select incorrect options.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NET_ADMIN

(NET_ADMIN) is correct because it is a Linux capability that can be added to a container's securityContext under the `capabilities.add` field. This capability allows the container to perform network administration tasks such as interface configuration, firewall management, and routing table manipulation, which are common in network-focused pods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RuntimeDefault

    Why it's wrong here

    RuntimeDefault is not a Linux capability but a seccomp profile type. In Kubernetes, seccomp profiles are specified under securityContext.seccompProfile with types like RuntimeDefault, Localhost, or Unconfined, while capabilities are listed under capabilities.add. Therefore, RuntimeDefault cannot be added as a container capability and is an incorrect answer.

  • ✗

    CAP_SYS_ADMIN

    Why it's wrong here

    CAP_SYS_ADMIN is a valid kernel capability, but Kubernetes capability names omit the CAP_ prefix. Writing CAP_SYS_ADMIN in a pod specification would cause a schema validation error; the correct entry would be SYS_ADMIN. Even though SYS_ADMIN exists, this option as presented is invalid due to the prefix, so it is wrong.

  • ✓

    NET_ADMIN

    Why this is correct

    NET_ADMIN is the Kubernetes name for the Linux capability CAP_NET_ADMIN, which permits operations such as configuring network interfaces, modifying routing tables, and managing firewall rules. It is a legitimate capability that can be added to a container's security context, making it one of the three correct answers.

  • ✓

    CHOWN

    Why this is correct

    CHOWN corresponds to CAP_CHOWN, which allows a process to change file ownership using chown, fchown, and lchown system calls. This is a standard, often-granted capability and is correctly referenced in Kubernetes without the CAP_ prefix, so it is a valid correct choice.

  • ✓

    SYS_TIME

    Why this is correct

    SYS_TIME is the Kubernetes representation of CAP_SYS_TIME, which grants the ability to set the system clock and real-time clock. This capability is explicitly addable via securityContext.capabilities.add, and since it is correctly named without the CAP_ prefix, it is a correct answer.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.