CKAD Practice Question: Application Environment, Configuration and Security
Which TWO actions can help prevent a container from being compromised if an attacker gains access? (Select 2)
⚠ Common exam trap
CNCF often tests the misconception that running as a non-root user (e.g., `runAsUser: 1000`) is sufficient, but the trap here is that `runAsUser: 0` explicitly sets root, which is a common mistake when candidates confuse 'default' with 'secure'—always drop all capabilities and make the filesystem read-only for defense in depth.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Setting securityContext.readOnlyRootFilesystem: true
Setting `securityContext.readOnlyRootFilesystem: true` makes the container's root filesystem read-only, preventing an attacker who gains access from modifying system binaries, libraries, or configuration files. This is a key defense-in-depth measure that limits the impact of a compromise by restricting write access to only explicitly mounted volumes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Setting securityContext.readOnlyRootFilesystem: true
Why this is correct
Setting readOnlyRootFilesystem to true mounts the container's root filesystem as read-only, so even a compromised process cannot modify binaries, libraries, or write new files to the container layer. Any legitimate writes must go to explicitly mounted writable volumes, which sharply limits the blast radius of an attack. This is a strong defense-in-depth control that complements other securityContext settings.
- ✗
Setting automountServiceAccountToken: true
Why it's wrong here
Leaving automountServiceAccountToken at true (or explicitly setting it true) automatically mounts the pod's service account JWT into the container at /var/run/secrets/kubernetes.io/serviceaccount. An attacker who compromises the container can then use that token to authenticate to the Kubernetes API and potentially escalate to cluster-wide actions, so the secure practice is to set it to false or explicitly disable the mount.
- ✓
Setting securityContext.capabilities.drop: ["ALL"]
Why this is correct
Dropping ALL Linux capabilities with capabilities.drop: ['ALL'] removes every privileged operation that the container process could invoke, such as mounting filesystems, sending raw packets, or changing file ownership, regardless of whether the process runs as root. Since capabilities are the granular permissions the kernel grants to processes, dropping them enforces least privilege and significantly reduces the ways an attack can pivot to the host or other resources.
- ✗
Setting securityContext.allowPrivilegeEscalation: true
Why it's wrong here
Configuring allowPrivilegeEscalation: true explicitly permits a process to gain more privileges than its parent, including via setuid executables, file capabilities, or other mechanisms. This setting essentially negates many other security controls because it allows the containerized process to elevate its effective UID or capabilities after it has been exploited, so it should be set to false to block such escape vectors.
- ✗
Setting securityContext.runAsUser: 0
Why it's wrong here
Setting runAsUser: 0 makes the container run as the root user, which inside a container means UID 0 with full access to the container's files and processes and many kernel permissions. If an attacker compromises the application, they inherit that root-level power, making it trivial to escape the container's restrictions or damage the host. The recommended practice is to run with a non-root UID, often combined with readOnlyRootFilesystem and dropped capabilities.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.