CKAD Practice Question: Application Environment, Configuration and Security
Which THREE of the following are valid fields in a SecurityContext at the container level? (Select three.)
⚠ Common exam trap
The exam often tests the distinction between Pod-level and container-level SecurityContext fields. A common trap is confusing fsGroup and sysctls, which are only valid at the Pod level, with runAsUser, which is valid at both levels. Candidates may mistakenly select sysctls as container-level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
runAsUser
The correct three options are B, C, and D. Option B (runAsUser) sets the user ID for container processes and is valid at container level. Option C (readOnlyRootFilesystem) mounts the root filesystem as read-only. Option D (capabilities) manages Linux capabilities. Option A (fsGroup) is a Pod-level SecurityContext field, not container-level. Option E (sysctls) is also a Pod-level field and cannot be set at the container level. Therefore, B, C, and D are the valid container-level fields.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
fsGroup
Why it's wrong here
fsGroup is a Pod-level SecurityContext field, not a valid container-level option. It controls group ownership of volumes mounted into the Pod, and optionally sets the group ID for files in those volumes. Attempting to specify fsGroup within a container's securityContext will cause an error, as it does not apply to individual containers.
- ✓
runAsUser
Why this is correct
runAsUser is a valid container-level SecurityContext field that specifies the user ID for the container's primary process. When set at the container level, it overrides any runAsUser value defined at the Pod level. This is essential for ensuring containers run as a non-root user, reducing the risk of privilege escalation.
- ✓
readOnlyRootFilesystem
Why this is correct
readOnlyRootFilesystem is a valid container-level SecurityContext field that mounts the container's root filesystem as read-only. Any writes to the root filesystem will fail, so applications must use mounted volumes or tmpfs for temporary data. This is a strong hardening technique to prevent attackers from modifying binaries or configuration files at runtime.
- ✓
capabilities
Why this is correct
capabilities is a valid container-level SecurityContext field that manages Linux capabilities for the container's main process. It allows adding or dropping specific privileges, such as dropping all capabilities or adding NET_BIND_SERVICE. This provides fine-grained control over what the container can do, separate from the Pod-level settings.
- ✗
sysctls
Why it's wrong here
sysctls is a Pod-level SecurityContext field used to set kernel parameters at the Pod level, not within a container's securityContext. It is restricted to namespaced sysctls for safety, and misconfiguration can affect the entire node. Container-level securityContext does not support sysctls, so this field is invalid there.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.