Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which THREE of the following are valid fields in a PodSecurityContext?

⚠ Common exam trap

CNCF often tests the distinction between PodSecurityContext and container SecurityContext, trapping candidates who assume all security-related fields (like capabilities or allowPrivilegeEscalation) are valid at the pod level when they are actually container-specific.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

fsGroup

fsGroup (A) is a valid PodSecurityContext field that sets a supplemental group ID applied to all containers in the pod, used for volume ownership and permissions. seccompProfile (C) is valid at the pod level and defines the seccomp profile applied to all containers in the pod. runAsNonRoot (D) is a valid PodSecurityContext field that ensures containers run as a non-root user by validating the image's USER directive. capabilities (B) and allowPrivilegeEscalation (E) are not PodSecurityContext fields; they belong to the container-level SecurityContext, not the pod-level one.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    fsGroup

    Why this is correct

    fsGroup is a valid PodSecurityContext field. It sets the supplementary group ID applied to all containers in the pod, and Kubernetes recursively changes ownership of mounted volumes to that group, enabling shared volume access across containers.

  • ✗

    capabilities

    Why it's wrong here

    This is a container-level SecurityContext field, not pod-level.

  • ✓

    seccompProfile

    Why this is correct

    `seccompProfile` is a legitimate PodSecurityContext field, letting you set a seccomp profile for all containers in the pod. It satisfies the stem's requirement for a valid PodSecurityContext field, unlike container-only settings such as `capabilities` or `allowPrivilegeEscalation`, which belong to SecurityContext instead.

  • ✓

    runAsNonRoot

    Why this is correct

    runAsNonRoot is a valid PodSecurityContext field, accepting a boolean that forces the container's process to run as a non-root UID. The kubelet validates the image's user against this setting and refuses to start the container if it would run as UID 0.

  • ✗

    allowPrivilegeEscalation

    Why it's wrong here

    allowPrivilegeEscalation belongs to the container's securityContext, not the PodSecurityContext, so it cannot appear as a pod-level field. It is tempting because it genuinely controls whether a process can gain more privileges than its parent, which is exactly what you would set per container when hardening individual workloads against setuid binaries.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.