CKAD Practice Question: Application Environment, Configuration and Security
You need to create a Pod that runs with a specific non-root user (UID 1000), prevents privilege escalation, and mounts the container's filesystem as read-only. Which securityContext field is NOT required to achieve these requirements?
⚠ Common exam trap
Candidates often assume runAsGroup is mandatory alongside runAsUser for non-root execution, but the CKAD exam tests that only the user ID is required unless a specific group is explicitly needed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
runAsGroup: 1000
(runAsGroup: 1000) is not required because the requirement only specifies a non-root user (UID 1000) and does not mandate a specific group ID. The runAsGroup field sets the primary group for the container's processes, but it is optional; without it, the container will use the default group associated with the user or the container's default group. The other options are necessary: runAsUser: 1000 sets the user, readOnlyRootFilesystem: true makes the filesystem read-only, and allowPrivilegeEscalation: false prevents privilege escalation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
runAsUser: 1000
Why it's wrong here
To satisfy a non-root constraint, you must set runAsUser to a numeric UID other than 0, such as 1000. Without this field, the container inherits the image's default user, which is often root, directly violating the requirement. This field is the primary mechanism for enforcing a non-root identity, making it a mandatory part of the pod's security context, not the optional setting.
- ✓
runAsGroup: 1000
Why this is correct
The requirement only specifies a non-root user, not a specific group. runAsGroup, if omitted, leaves the container's primary GID unchanged from the image or the user's default group, which does not affect the process's non-root status. Since no group requirement is stated, runAsGroup is optional and therefore the correct answer to a question asking which setting is not required.
- ✗
readOnlyRootFilesystem: true
Why it's wrong here
A writable root filesystem lets a compromised non-root process modify binaries or system files, weakening the isolation provided by a non-root UID. Setting readOnlyRootFilesystem to true forces all writes to ephemeral volumes and prevents changes to the rootfs, which is a standard hardening requirement for non-root workloads. Thus, it is a required security control, not the optional field.
- ✗
allowPrivilegeEscalation: false
Why it's wrong here
Even with a non-root UID, a container might still escalate privileges through setuid binaries or retained kernel capabilities. Setting allowPrivilegeEscalation to false disables such mechanisms, ensuring the process cannot gain additional privileges beyond its starting UID. This is essential to genuinely enforce non-root execution, so it is a required setting and not the optional one.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.