CKAD Practice Question: Application Environment, Configuration and Security
You want to restrict a Pod to only run with a seccomp profile of 'RuntimeDefault'. Which SecurityContext field should you set?
⚠ Common exam trap
Watch out — candidates often confuse seccomp with other security mechanisms like AppArmor or SELinux, or think that `capabilities` can restrict syscalls, when in fact seccomp is the only field that directly controls syscall filtering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
seccompProfile
The `seccompProfile` field in a Pod's SecurityContext allows you to specify a seccomp profile to restrict system calls. Setting it to `RuntimeDefault` applies the container runtime's default seccomp profile, which blocks a set of dangerous syscalls while allowing normal operation. This is the correct field to enforce a seccomp profile of 'RuntimeDefault'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
appArmorProfile
Why it's wrong here
AppArmor is a Linux security module (LSM) that uses path-based profiles to restrict program access to files, networks, and other resources. In Kubernetes, it is configured via the `container.apparmor.security.beta.kubernetes.io/<container-name>` annotation or the `appArmorProfile` field, but it is entirely separate from seccomp, which filters raw system calls. Selecting AppArmor does not influence seccomp restrictions, so this option cannot satisfy the requirement to run with a seccomp profile. To enforce seccomp, you must set `seccompProfile` under the pod or container's security context.
- ✗
capabilities
Why it's wrong here
Linux capabilities are discrete privileges (e.g., CAP_NET_ADMIN, CAP_SYS_TIME) that partition the power of root; they are managed in Kubernetes via the `capabilities` field in `securityContext`. Capabilities control what privileged operations a process may perform, but they do not filter system calls themselves. Seccomp, in contrast, provides a syscall-level sandbox that can deny or allow specific syscalls regardless of capability grants. Removing or adding capabilities does not install or define a seccomp profile, so this field is irrelevant to the requirement.
- ✗
seLinuxOptions
Why it's wrong here
SELinux is another LSM that enforces mandatory access control using labels (e.g., type and role) to govern file, process, and port access. In Kubernetes, `seLinuxOptions` sets the SELinux context for a container, which determines its security label and policy enforcement. SELinux works at the object's permission level, not at the syscall filtering layer that seccomp operates on. Setting `seLinuxOptions` does not create any seccomp profile, so it fails the stated requirement.
- ✓
seccompProfile
Why this is correct
This is the correct field in the `securityContext` (either at pod or container level) to specify a seccomp profile that restricts system calls. By setting `type: RuntimeDefault`, you tell the container runtime (e.g., containerd, CRI-O) to use its default seccomp profile, which blocks a set of dangerous or unused syscalls. For custom filters, you can point to a `Localhost` profile using the `localhostProfile` field and a node's profile directory. This directly satisfies the requirement of running with a seccomp profile.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.