Courseiva
System Hardening →hardMultiple Choice

CKS System Hardening Practice Question

A cluster administrator wants to apply a custom seccomp profile located at '/var/lib/kubelet/seccomp/audit.json' to a pod. Which YAML snippet correctly configures the pod's security context to use this profile?

⚠ Common exam trap

CNCF often tests the misconception that `localhostProfile` requires the full filesystem path, when in fact only the filename is needed because Kubernetes prepends the kubelet's seccomp root directory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

seccompProfile: type: Localhost localhostProfile: audit.json

When using a custom seccomp profile stored on the node, the `type` must be `Localhost` and the `localhostProfile` must specify only the filename (not the full path). Kubernetes automatically prepends the path `/var/lib/kubelet/seccomp/` to the filename, so `audit.json` resolves to the correct location.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    seccompProfile: type: Localhost localhostProfile: audit.json

    Why this is correct

    This is the correct configuration. With type: Localhost, the kubelet is instructed to load a seccomp profile from the node's seccomp root directory (default /var/lib/kubelet/seccomp). The localhostProfile field must contain only the filename, relative to that directory, not a full path. Here, 'audit.json' is exactly that, so the kubelet will correctly locate the profile at /var/lib/kubelet/seccomp/audit.json and apply its rules to the container.

  • ✗

    seccompProfile: type: Unconfined localhostProfile: audit.json

    Why it's wrong here

    Setting type: Unconfined explicitly disables seccomp filtering for the container, meaning the kernel will not restrict syscalls at all. Because Unconfined is a special mode that bypasses seccomp, the localhostProfile field is meaningless and is ignored by Kubernetes; you can't pair a custom profile with a mode that intentionally turns off seccomp. In practice, this combination would result in the container running without any seccomp protection, defeating the administrator's goal of using the custom audit profile.

  • ✗

    seccompProfile: type: Localhost localhostProfile: /var/lib/kubelet/seccomp/audit.json

    Why it's wrong here

    The localhostProfile field is not an absolute path; it is a filename relative to the seccomp root directory on the node, which defaults to /var/lib/kubelet/seccomp. If you specify /var/lib/kubelet/seccomp/audit.json, the kubelet will incorrectly look for that full string inside the root, effectively referencing /var/lib/kubelet/seccomp/var/lib/kubelet/seccomp/audit.json, which does not exist. Therefore, only 'audit.json' should be provided, as the kubelet automatically prepends the configured root path.

  • ✗

    seccompProfile: type: RuntimeDefault localhostProfile: audit.json

    Why it's wrong here

    The RuntimeDefault type tells the container runtime (e.g., containerd or CRI-O) to apply its own built-in default seccomp profile, which is embedded in the runtime and not stored as a local file. Because there is no file to reference, the localhostProfile field is entirely inapplicable and will be ignored; specifying it alongside RuntimeDefault is contradictory and won't cause your custom profile to be loaded. The result is that the container gets the runtime's default rules, not the custom audit.json profile the administrator intended to enforce.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator creates a custom seccomp profile and wants to apply it to a pod. The profile file is named 'audit.json' and is placed in the default seccomp directory on the node. Which securityContext field should be used?

medium
  • A.securityContext.seccompProfile.type: Localhost and securityContext.seccompProfile.file: audit.json
  • B.securityContext.seccompProfile.type: Localhost and securityContext.seccompProfile.profile: audit.json
  • ✓ C.securityContext.seccompProfile.type: Localhost and securityContext.seccompProfile.localhostProfile: audit.json
  • D.seccomp.security.alpha.kubernetes.io/pod: localhost/audit.json

Why C: In Kubernetes, when using a custom seccomp profile stored on the node's default seccomp directory, the `securityContext.seccompProfile.type` must be set to `Localhost` and the profile filename is specified via the `localhostProfile` field. This field expects the filename (e.g., `audit.json`) relative to the node's default seccomp path (`/var/lib/kubelet/seccomp`). The `type: Localhost` instructs kubelet to load the profile from the node's filesystem.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.