CKS System Hardening Practice Question
A container is running with the following securityContext:
securityContext: capabilities: drop: ["ALL"] add: ["NET_BIND_SERVICE"]
Which capabilities will the container have?
⚠ Common exam trap
Kubernetes often tests the misconception that `drop: ["ALL"]` only removes non-default capabilities, or that adding a capability after dropping all restores the default set; the trap is that the order of operations is sequential and additive, so the final set is exactly what is added, not a union of defaults and additions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Only NET_BIND_SERVICE
The securityContext first drops all capabilities with `drop: ["ALL"]`, which removes every capability from the container's bounding set. Then `add: ["NET_BIND_SERVICE"]` adds back only that single capability. Therefore, the final effective set is exactly `NET_BIND_SERVICE`, making option B correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All capabilities except NET_BIND_SERVICE
Why it's wrong here
This option incorrectly suggests the container retains all default capabilities except NET_BIND_SERVICE. In Kubernetes, the `capabilities.drop: ["ALL"]` directive resets the capability bounding set to empty, removing every capability that a process could otherwise inherit, including all default capabilities granted by the container runtime. The subsequent `add: ["NET_BIND_SERVICE"]` then inserts exactly that single capability into the now-empty set. Consequently, the final capability set is exactly `NET_BIND_SERVICE`, not a full set minus one; the misconception is thinking of `drop` as removing a single capability when `ALL` is a wholesale reset.
- ✓
Only NET_BIND_SERVICE
Why this is correct
This is the correct interpretation: the container runs with exactly one Linux capability, `NET_BIND_SERVICE`. When `capabilities.drop` contains `ALL`, the container runtime begins with a completely empty capability set for the process, stripping away all default capabilities such as `CHOWN`, `DAC_OVERRIDE`, and `FOWNER`. Then `capabilities.add` with `NET_BIND_SERVICE` adds back just that one capability, allowing the process to bind to privileged ports (below 1024) but nothing else. This is a common least-privilege pattern for services that need to serve traffic on port 80 or 443.
- ✗
No capabilities
Why it's wrong here
This option mistakenly treats the `add` entry as irrelevant or assumes the container still has no capabilities because `drop: ["ALL"]` is present. However, the order of operations in Kubernetes capability handling is deterministic: drop first, then add. Even after dropping ALL, the explicit addition of `NET_BIND_SERVICE` means the final capability set is non-empty, and the process can bind to low-numbered ports. Thus, saying 'no capabilities' ignores the additive step and misreads the YAML semantics.
- ✗
All default capabilities plus NET_BIND_SERVICE
Why it's wrong here
This option presupposes that the default capabilities (the ones the container runtime would normally provide) survive the `drop: ["ALL"]` directive, and that `NET_BIND_SERVICE` is simply appended to that default set. In reality, `drop: ["ALL"]` is an absolute removal of every capability from the bounding set, overriding the runtime's defaults entirely. The `add` list then repopulates the set from scratch, so since only `NET_BIND_SERVICE` is added, the container does not have any of the default capabilities. This configuration intentionally eliminates the default set and starts clean, so claiming 'all default capabilities plus NET_BIND_SERVICE' is the opposite of what the YAML accomplishes.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.