CKAD Practice Question: Application Environment, Configuration and Security
Which THREE of the following are valid fields in a PodSecurityContext?
⚠ Common exam trap
CNCF often tests the distinction between PodSecurityContext and container SecurityContext, trapping candidates who assume all security-related fields (like capabilities or allowPrivilegeEscalation) are valid at the pod level when they are actually container-specific.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
fsGroup
fsGroup (A) is a valid PodSecurityContext field that sets a supplemental group ID applied to all containers in the pod, used for volume ownership and permissions. seccompProfile (C) is valid at the pod level and defines the seccomp profile applied to all containers in the pod. runAsNonRoot (D) is a valid PodSecurityContext field that ensures containers run as a non-root user by validating the image's USER directive. capabilities (B) and allowPrivilegeEscalation (E) are not PodSecurityContext fields; they belong to the container-level SecurityContext, not the pod-level one.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
fsGroup
Why this is correct
fsGroup is a valid PodSecurityContext field. It sets the supplementary group ID applied to all containers in the pod, and Kubernetes recursively changes ownership of mounted volumes to that group, enabling shared volume access across containers.
- ✗
capabilities
Why it's wrong here
This is a container-level SecurityContext field, not pod-level.
- ✓
seccompProfile
Why this is correct
`seccompProfile` is a legitimate PodSecurityContext field, letting you set a seccomp profile for all containers in the pod. It satisfies the stem's requirement for a valid PodSecurityContext field, unlike container-only settings such as `capabilities` or `allowPrivilegeEscalation`, which belong to SecurityContext instead.
- ✓
runAsNonRoot
Why this is correct
runAsNonRoot is a valid PodSecurityContext field, accepting a boolean that forces the container's process to run as a non-root UID. The kubelet validates the image's user against this setting and refuses to start the container if it would run as UID 0.
- ✗
allowPrivilegeEscalation
Why it's wrong here
allowPrivilegeEscalation belongs to the container's securityContext, not the PodSecurityContext, so it cannot appear as a pod-level field. It is tempting because it genuinely controls whether a process can gain more privileges than its parent, which is exactly what you would set per container when hardening individual workloads against setuid binaries.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.