CKAD Practice Question: Application Environment, Configuration and Security
Which THREE of the following are valid fields in a PodSecurityContext that affect container security? (Select 3)
⚠ Common exam trap
Test-takers frequently confuse PodSecurityContext fields (which affect all containers in the pod) with container-level SecurityContext fields (which affect only a single container), leading them to incorrectly select 'capabilities' or 'privileged' as pod-level options.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
runAsUser
(runAsUser) is correct because it is a valid field in a PodSecurityContext that specifies the user ID (UID) under which all containers in the pod run. This field directly affects container security by controlling privilege levels and access to host resources, overriding the container's default user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
capabilities
Why it's wrong here
The capabilities field is not a member of PodSecurityContext; it belongs to the container-level securityContext, where it adds or removes Linux capabilities for that specific container. Since the question asks about podsec — i.e., PodSecurityContext — capabilities is invalid here. You cannot set per-container capabilities from the pod-level security context.
- ✓
runAsUser
Why this is correct
runAsUser is a valid field in PodSecurityContext, specifying the numeric UID that all containers in the pod must run with. It overrides any user defined in the container image, enforcing a non-root user consistently across the pod. This field is also available at the container level, but when set at the pod level it applies to every container unless an individual container overrides it.
- ✓
runAsGroup
Why this is correct
runAsGroup is also a valid PodSecurityContext field, setting the primary group ID (GID) for all processes in the pod's containers. It is typically paired with runAsUser to control both UID and GID, and it also determines the owner of files created in mounted volumes when combined with fsGroup. If omitted, the process group defaults to the group of the effective user, which may be root if the image runs as root.
- ✗
privileged
Why it's wrong here
privileged is a container-level securityContext option, not a PodSecurityContext field. It elevates a single container to privileged mode, giving it access to all host devices and capabilities that bypass normal kernel restrictions. The pod-level security context has no privileged field; you can only set it individually on each container's securityContext.
- ✓
fsGroup
Why this is correct
fsGroup is a valid field in PodSecurityContext that sets a supplemental group ID for all volumes mounted in the pod. The kubelet changes ownership of those volumes to include this GID, enabling containers to read and write volume data. It also gives the group-based access to the volume's files, and it can be combined with runAsGroup and runAsUser for fine-grained permission control.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.