Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

You want to restrict a Pod to only run with a seccomp profile of 'RuntimeDefault'. Which SecurityContext field should you set?

⚠ Common exam trap

Watch out — candidates often confuse seccomp with other security mechanisms like AppArmor or SELinux, or think that `capabilities` can restrict syscalls, when in fact seccomp is the only field that directly controls syscall filtering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

seccompProfile

The `seccompProfile` field in a Pod's SecurityContext allows you to specify a seccomp profile to restrict system calls. Setting it to `RuntimeDefault` applies the container runtime's default seccomp profile, which blocks a set of dangerous syscalls while allowing normal operation. This is the correct field to enforce a seccomp profile of 'RuntimeDefault'.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    appArmorProfile

    Why it's wrong here

    AppArmor is a Linux security module (LSM) that uses path-based profiles to restrict program access to files, networks, and other resources. In Kubernetes, it is configured via the `container.apparmor.security.beta.kubernetes.io/<container-name>` annotation or the `appArmorProfile` field, but it is entirely separate from seccomp, which filters raw system calls. Selecting AppArmor does not influence seccomp restrictions, so this option cannot satisfy the requirement to run with a seccomp profile. To enforce seccomp, you must set `seccompProfile` under the pod or container's security context.

  • ✗

    capabilities

    Why it's wrong here

    Linux capabilities are discrete privileges (e.g., CAP_NET_ADMIN, CAP_SYS_TIME) that partition the power of root; they are managed in Kubernetes via the `capabilities` field in `securityContext`. Capabilities control what privileged operations a process may perform, but they do not filter system calls themselves. Seccomp, in contrast, provides a syscall-level sandbox that can deny or allow specific syscalls regardless of capability grants. Removing or adding capabilities does not install or define a seccomp profile, so this field is irrelevant to the requirement.

  • ✗

    seLinuxOptions

    Why it's wrong here

    SELinux is another LSM that enforces mandatory access control using labels (e.g., type and role) to govern file, process, and port access. In Kubernetes, `seLinuxOptions` sets the SELinux context for a container, which determines its security label and policy enforcement. SELinux works at the object's permission level, not at the syscall filtering layer that seccomp operates on. Setting `seLinuxOptions` does not create any seccomp profile, so it fails the stated requirement.

  • ✓

    seccompProfile

    Why this is correct

    This is the correct field in the `securityContext` (either at pod or container level) to specify a seccomp profile that restricts system calls. By setting `type: RuntimeDefault`, you tell the container runtime (e.g., containerd, CRI-O) to use its default seccomp profile, which blocks a set of dangerous or unused syscalls. For custom filters, you can point to a `Localhost` profile using the `localhostProfile` field and a node's profile directory. This directly satisfies the requirement of running with a seccomp profile.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.