Courseiva
System Hardening →hardMultiple Choice

CKS System Hardening Practice Question

A custom seccomp profile is created at /var/lib/kubelet/seccomp/custom-profile.json. Which YAML snippet applies this profile to a container?

⚠ Common exam trap

The CKS exam often tests the distinction between the `seccompProfile` field (correct in Kubernetes 1.19+) and the older `seccomp` annotation-based syntax, and candidates mistakenly choose option D because they remember the old annotation format or confuse `profile` with `localhostProfile`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

securityContext: seccompProfile: type: Localhost localhostProfile: custom-profile.json

When using a custom seccomp profile stored on the node, the `type: Localhost` field must be set, and the `localhostProfile` field specifies the filename (relative to the kubelet's seccomp root directory, which defaults to `/var/lib/kubelet/seccomp`). This configuration tells the container runtime to load the profile from the node's filesystem at the path `/var/lib/kubelet/seccomp/custom-profile.json`.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    securityContext: seccompProfile: type: Localhost localhostProfile: custom-profile.json

    Why this is correct

    The correct structure uses seccompProfile.type: Localhost to indicate that a profile file is stored on the node, and localhostProfile: custom-profile.json to reference that specific file. The kubelet looks for the file in the node's seccomp profile directory (typically /var/lib/kubelet/seccomp) and loads it to restrict syscalls for the container. This is the only syntax in the current Kubernetes API that directly applies a custom local seccomp profile.

  • ✗

    securityContext: seccompProfile: type: Unconfined

    Why it's wrong here

    Setting type: Unconfined explicitly disables seccomp for the container, meaning no syscall filter is loaded and the kernel's default seccomp policy (which is effectively no seccomp restriction) applies. This does not reference any profile file, so it cannot enforce a custom profile. It might be a valid seccompProfile type, but it does not achieve the goal of applying a custom syscall allow/deny list.

  • ✗

    securityContext: seccompProfile: type: RuntimeDefault localhostProfile: custom-profile.json

    Why it's wrong here

    The type RuntimeDefault instructs the container runtime to use its own predefined seccomp profile (e.g., Docker's default profile in containerd or CRI-O). In this mode, the localhostProfile field is not allowed or meaningful; the Kubernetes API validation expects localhostProfile to be used only when type is Localhost. Including both will cause the manifest to be rejected or make the runtime default override the custom profile, so the custom profile is never applied.

  • ✗

    securityContext: seccomp: profile: custom-profile.json

    Why it's wrong here

    The field seccomp does not exist in the Kubernetes PodSecurityContext or ContainerSecurityContext API. The correct field is seccompProfile, which is an object containing type and optionally localhostProfile. Using the old-style key like seccomp.profile would fail schema validation or be ignored, so the custom profile would not be loaded and the container might run without any seccomp restrictions. This is a common syntax error when migrating from legacy alpha annotations.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.