CKS Minimize Microservice Vulnerabilities Practice Question
A cluster administrator needs to run a workload that uses gVisor (runsc) for container sandboxing. Which Kubernetes resource is required to enable this?
⚠ Common exam trap
Watch out — candidates often confuse RuntimeClass with PodSecurityPolicy or PriorityClass, thinking that sandboxing is enforced through security policies or scheduling priorities, rather than understanding that RuntimeClass is the explicit Kubernetes resource for selecting a different container runtime per pod.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
RuntimeClass
A RuntimeClass resource is required to enable gVisor (runsc) because it defines the container runtime configuration that should be used for pods. By creating a RuntimeClass with the handler set to 'runsc', the cluster administrator can instruct the kubelet to use gVisor as the OCI-compatible runtime for sandboxing, providing an additional security layer through a user-space kernel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
RuntimeClass
Why this is correct
RuntimeClass is a cluster-level resource that defines a handler (e.g., 'runsc' or 'gvisor') that the Kubernetes node's CRI runtime should use to launch the pod. A pod can reference a RuntimeClass via `spec.runtimeClassName`, and the kubelet then passes the handler to the runtime (like containerd) to run the container with that specific runtime engine. This is precisely how gVisor is selected, since multiple runtimes can be installed on the same node and chosen per-pod. Importantly, the RuntimeClass must be created by an administrator, and the handler must match a runtime configured on the node.
- ✗
PriorityClass
Why it's wrong here
It affects the scheduling order and preemption of pods based on pod priority; it does not influence which container runtime is chosen to run the containers. Kubernetes scheduler uses priority to decide which pending pods to schedule and which to preempt, but the runtime is determined by the RuntimeClass field on the pod spec. Therefore, using a PriorityClass would not cause a workload to run under gVisor; it only impacts scheduling guarantees, not the runtime environment.
- ✗
NetworkPolicy
Why it's wrong here
NetworkPolicy is a namespaced resource that defines ingress and egress rules for pods, enforcing at the network layer via CNI plugins. It governs which pods can communicate with each other and other network endpoints, but it doesn't affect the runtime or sandboxing of the workload. gVisor is a user-space kernel that intercepts system calls; that selection is done via RuntimeClass, not via network policies. Thus, NetworkPolicy has no role in determining whether a pod uses gVisor.
- ✗
PodSecurityPolicy
Why it's wrong here
PodSecurityPolicy (PSP) was a cluster-level admission controller that enforced security constraints like privileged mode, host namespaces, and allowed capabilities. While it could restrict certain fields of a pod spec, it never set the container runtime; that is a function of the RuntimeClass. In fact, PSP is deprecated and removed in Kubernetes v1.25, and it focuses on admission-time validation, not on runtime selection. Hence, a PSP cannot make a workload use gVisor; it only ensures that the pod meets certain security standards.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.