Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

A cluster administrator wants to run some workloads in a sandboxed environment using gVisor. Which Kubernetes resource must be created first to allow pods to request the gVisor runtime?

⚠ Common exam trap

Kubernetes often tests the distinction between creating a resource (RuntimeClass) versus referencing it in a pod spec, so candidates mistakenly think adding the `runtimeClass` field directly to the pod is sufficient without first creating the RuntimeClass object.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a RuntimeClass resource that specifies the gVisor runtime handler

C is correct because in Kubernetes, a RuntimeClass resource must be created to define a container runtime configuration, such as gVisor. This resource specifies a runtime handler (e.g., 'runsc') that the container runtime uses to run pods in a sandboxed environment. Pods can then reference this RuntimeClass via the `runtimeClassName` field in their spec to request the gVisor runtime.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a new PodSecurityPolicy that allows the gVisor runtime

    Why it's wrong here

    PodSecurityPolicy is a deprecated admission-control resource that was removed in Kubernetes 1.25, and it never had any capability to influence which OCI runtime executes a container. Even if a PSP were written to 'allow' gVisor, PSPs only constrain security context fields like privileged flags, host namespaces, or volume types. Runtime selection is entirely handled by the kubelet inspecting the pod's RuntimeClass reference, so creating a PSP does not enable or configure gVisor behavior.

  • ✗

    Create a custom resource definition for the runtime

    Why it's wrong here

    RuntimeClass is not a custom resource; it is a built-in API type in the node.k8s.io/v1 API group that the Kubernetes control plane natively understands. Defining a CustomResourceDefinition would invent a new extension resource that the kubelet and scheduler never consult for runtime selection. The correct administrative step is to create a RuntimeClass object with the handler field set to runsc, not to define a schema for a custom object that has no effect on container execution.

  • ✓

    Create a RuntimeClass resource that specifies the gVisor runtime handler

    Why this is correct

    A RuntimeClass is a cluster-scoped, built-in object whose handler field names the runtime configuration registered on each node, for example ',runsc,' for gVisor. When a pod's spec sets runtimeClassName to reference this object, the kubelet passes the handler to the container runtime (like containerd), which then launches the pod under the gVisor sandbox. Creating this RuntimeClass resource is the mandatory administrative step, as it establishes the mapping between a simple name and the actual OCI runtime handler that workloads will use.

  • ✗

    Add a `runtimeClass` field to the pod spec

    Why it's wrong here

    Adding the runtimeClass field to a pod spec is only a reference to a RuntimeClass object that must already exist in the cluster; the field itself contains no runtime configuration. If the administrator has not created the RuntimeClass, the kubelet cannot resolve the handler and the pod creation fails with an error like 'RuntimeClass node.k8s.io/v1 not found.' Therefore, the proper sequence is to create the RuntimeClass resource first, and then have workloads reference it by name in their pod templates.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator wants to use gVisor to sandbox containers in a Kubernetes cluster. Which resource must be created to enable this?

medium
  • ✓ A.RuntimeClass with handler: runsc
  • B.DaemonSet to install gVisor on nodes
  • C.PodSecurityPolicy with gVisor enabled
  • D.SecurityContext with runtime: gvisor

Why A: To use gVisor as a container runtime sandbox in Kubernetes, you must create a RuntimeClass resource with the handler set to 'runsc'. This tells the kubelet which runtime handler to use when running pods that reference this RuntimeClass, enabling gVisor's user-space kernel (runsc) to intercept and sandbox system calls.

Variation 2. A cluster administrator needs to run a workload that uses gVisor (runsc) for container sandboxing. Which Kubernetes resource is required to enable this?

medium
  • ✓ A.RuntimeClass
  • B.PriorityClass
  • C.NetworkPolicy
  • D.PodSecurityPolicy

Why A: A RuntimeClass resource is required to enable gVisor (runsc) because it defines the container runtime configuration that should be used for pods. By creating a RuntimeClass with the handler set to 'runsc', the cluster administrator can instruct the kubelet to use gVisor as the OCI-compatible runtime for sandboxing, providing an additional security layer through a user-space kernel.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.