CKS Pod Security Standards (PSS) Practice Question
A container needs to run with the NET_ADMIN capability to modify network settings. The cluster enforces the baseline Pod Security Standard. Which securityContext configurations are valid? (Select all that apply.)
⚠ Common exam trap
Candidates often assume that dropping all capabilities is required (as in the restricted profile) even when the baseline profile is in effect. Both option A and C are valid under baseline; the trap is thinking only one is correct.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
capabilities: add: ["NET_ADMIN"]
Under the baseline Pod Security Standard (PSS), both options A and C are valid because the baseline profile permits adding specific capabilities like NET_ADMIN. Option A directly adds NET_ADMIN to the container's capabilities. Option C drops all capabilities first and then adds NET_ADMIN, which is also compliant because dropping all is allowed under baseline, and then adding NET_ADMIN is permitted. Option B uses an invalid field name (linuxCapabilities should be capabilities). Option D drops NET_ADMIN, which would remove the required capability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
capabilities: add: ["NET_ADMIN"]
Why this is correct
Correct. Adding NET_ADMIN directly is allowed under the baseline PSS.
- ✗
linuxCapabilities: add: ["NET_ADMIN"]
Why it's wrong here
Incorrect. The correct field name is 'capabilities', not 'linuxCapabilities'.
- ✓
capabilities: drop: ["ALL"] add: ["NET_ADMIN"]
Why this is correct
Correct. Dropping all capabilities and then adding NET_ADMIN is also compliant under the baseline PSS.
- ✗
capabilities: drop: ["NET_ADMIN"]
Why it's wrong here
Incorrect. Dropping NET_ADMIN would remove the required capability.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.