Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

Which THREE of the following are valid fields in a SecurityContext at the container level? (Select three.)

⚠ Common exam trap

The exam often tests the distinction between Pod-level and container-level SecurityContext fields. A common trap is confusing fsGroup and sysctls, which are only valid at the Pod level, with runAsUser, which is valid at both levels. Candidates may mistakenly select sysctls as container-level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

runAsUser

The correct three options are B, C, and D. Option B (runAsUser) sets the user ID for container processes and is valid at container level. Option C (readOnlyRootFilesystem) mounts the root filesystem as read-only. Option D (capabilities) manages Linux capabilities. Option A (fsGroup) is a Pod-level SecurityContext field, not container-level. Option E (sysctls) is also a Pod-level field and cannot be set at the container level. Therefore, B, C, and D are the valid container-level fields.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    fsGroup

    Why it's wrong here

    fsGroup is a Pod-level SecurityContext field, not a valid container-level option. It controls group ownership of volumes mounted into the Pod, and optionally sets the group ID for files in those volumes. Attempting to specify fsGroup within a container's securityContext will cause an error, as it does not apply to individual containers.

  • ✓

    runAsUser

    Why this is correct

    runAsUser is a valid container-level SecurityContext field that specifies the user ID for the container's primary process. When set at the container level, it overrides any runAsUser value defined at the Pod level. This is essential for ensuring containers run as a non-root user, reducing the risk of privilege escalation.

  • ✓

    readOnlyRootFilesystem

    Why this is correct

    readOnlyRootFilesystem is a valid container-level SecurityContext field that mounts the container's root filesystem as read-only. Any writes to the root filesystem will fail, so applications must use mounted volumes or tmpfs for temporary data. This is a strong hardening technique to prevent attackers from modifying binaries or configuration files at runtime.

  • ✓

    capabilities

    Why this is correct

    capabilities is a valid container-level SecurityContext field that manages Linux capabilities for the container's main process. It allows adding or dropping specific privileges, such as dropping all capabilities or adding NET_BIND_SERVICE. This provides fine-grained control over what the container can do, separate from the Pod-level settings.

  • ✗

    sysctls

    Why it's wrong here

    sysctls is a Pod-level SecurityContext field used to set kernel parameters at the Pod level, not within a container's securityContext. It is restricted to namespaced sysctls for safety, and misconfiguration can affect the entire node. Container-level securityContext does not support sysctls, so this field is invalid there.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.