CKS System Hardening Practice Question
A container runs as non-root and needs to perform operations that require CAP_SYS_PTRACE. Which YAML snippet correctly adds only this capability while following the principle of least privilege?
⚠ Common exam trap
CNCF often tests the misconception that simply adding a capability is sufficient, but the trap is that candidates forget to drop all other capabilities first, leaving the container with more privileges than intended.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
securityContext: capabilities: drop: ['ALL'] add: ['SYS_PTRACE']
It first drops all capabilities with `drop: ['ALL']` and then explicitly adds only `SYS_PTRACE`, ensuring the container runs with the minimum privileges required. This follows the principle of least privilege by removing any inherited or default capabilities before granting only the needed one. In Kubernetes, capabilities are Linux kernel capabilities; dropping all and adding only what is necessary is the recommended security practice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
securityContext: capabilities: add: ['SYS_PTRACE']
Why it's wrong here
This configuration adds SYS_PTRACE to the container's existing default capability set, leaving all other default capabilities (e.g., NET_RAW, SYS_CHROOT, DAC_OVERRIDE) enabled. While it grants the needed tracing operation, it violates least privilege because the container retains capabilities irrelevant to its task, widening the attack surface if the process is compromised.
- ✓
securityContext: capabilities: drop: ['ALL'] add: ['SYS_PTRACE']
Why this is correct
This explicitly drops every capability first, then adds only SYS_PTRACE, resulting in a minimal capability set scoped to the required operation. This follows the least-privilege principle: the container receives exactly one Linux capability, reducing the kernel attack surface to the narrowest possible for the task.
- ✗
securityContext: capabilities: drop: ['ALL']
Why it's wrong here
Dropping all capabilities yields an empty capability set, so the process lacks SYS_PTRACE needed for ptrace-based operations. The container will receive permission denied (EPERM) when attempting the operation; this configuration fails the functionality requirement, although it is secure from a least-privilege perspective.
- ✗
securityContext: privileged: true
Why it's wrong here
Setting privileged: true grants the container every capability on the host and disables most security mechanisms (e.g., seccomp, AppArmor), effectively giving it near-root power over the host. This is far more than the single SYS_PTRACE needed and introduces a severe privilege escalation risk, especially if the container is compromised.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security policy requires that all containers in the 'staging' namespace drop all Linux capabilities and only add the necessary ones. Which pod security context configuration achieves this?
medium- ✓ A.capabilities.drop: ["ALL"] capabilities.add: ["NET_BIND_SERVICE"]
- B.cap_drop: ["NET_RAW"]
- C.cap_add: ["ALL"]
- D.cap_add: ["NET_BIND_SERVICE"]
Why A: It drops all Linux capabilities using `capabilities.drop: ["ALL"]` and then explicitly adds only the necessary `NET_BIND_SERVICE` capability via `capabilities.add: ["NET_BIND_SERVICE"]`. This adheres to the principle of least privilege by starting from a clean slate and granting only the required capability. In Kubernetes security contexts, the correct keys are `capabilities.drop` and `capabilities.add` under the `securityContext` field. Options B and D partially meet the requirement but do not drop all capabilities; Option C adds all capabilities, violating the policy.
Variation 2. A security team wants to ensure that all containers in a pod run with only the minimum required Linux capabilities. Which of the following approaches is BEST?
medium- A.Set securityContext.capabilities.drop: ['ALL'] with no add
- B.Leave capabilities unset to use the default set
- C.Add only the necessary capabilities without dropping
- ✓ D.Set securityContext.capabilities.drop: ['ALL'] and add only necessary capabilities
Why D: It implements the principle of least privilege by first dropping all capabilities with `drop: ['ALL']` and then explicitly adding back only those capabilities that are strictly necessary for the container to function. This ensures that the container runs with the absolute minimum set of Linux capabilities, reducing the attack surface and adhering to Kubernetes security best practices for system hardening.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.