Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

A developer asks you to run a container with gVisor runtime. The cluster has a RuntimeClass named 'gvisor' defined. Which field must be added to the Pod spec to use gVisor?

⚠ Common exam trap

The `runtimeClassName` field is a top-level field in the Pod spec (`spec.runtimeClassName`). A common mistake is setting it under `metadata` or `spec.containers[]`, or confusing it with the deprecated `runtimeClass` field. This question tests precise knowledge of the CNCF's Kubernetes API.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

spec.runtimeClassName: gvisor

The `runtimeClassName` field is a top-level field in the Pod spec (i.e., `spec.runtimeClassName`) that specifies the name of the RuntimeClass resource to use for running the Pod's containers. In this case, setting `spec.runtimeClassName: gvisor` instructs the kubelet to use the gVisor runtime (via the 'gvisor' RuntimeClass) for all containers in the Pod, enabling a sandboxed kernel for enhanced isolation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    spec.containers[0].runtimeClassName: gvisor

    Why it's wrong here

    The runtimeClassName field is not a valid field of a container in Kubernetes. It is a PodSpec-level field because the container runtime is chosen for the entire pod, not per-container; all containers in a pod must share the same sandbox. Placing it under spec.containers[0] would cause the API server to reject the Pod as invalid, and even if accepted, it would not affect the runtime used by that container.

  • ✗

    metadata.runtimeClassName: gvisor

    Why it's wrong here

    The metadata section stores identity and administrative information such as name, namespace, labels, and annotations. runtimeClassName belongs in the PodSpec, which is the structured schema under spec; placing it in metadata makes it an unrecognized field, and with strict API validation the Pod will be rejected. Even if the field were tolerated by a misconfigured API server, it would be ignored and have no effect on runtime selection.

  • ✗

    spec.runtimeClass: gvisor

    Why it's wrong here

    In a PodSpec, the correct field name is runtimeClassName, not runtimeClass. The term 'runtimeClass' refers to the cluster-scoped RuntimeClass resource (e.g., a YAML object of kind RuntimeClass) that defines a handler like runsc. While the field references that resource by name, the PodSpec field itself must be spelled runtimeClassName, so spec.runtimeClass is invalid and would fail schema validation.

  • ✓

    spec.runtimeClassName: gvisor

    Why this is correct

    This is the correct placement and spelling. The PodSpec's runtimeClassName field is a string that references the name of a RuntimeClass resource (such as one named 'gvisor') that the kubelet must use to run all containers in the pod. Setting it to 'gvisor' requires that a matching RuntimeClass object with the appropriate handler (e.g., 'runsc') exists in the cluster, and it ensures the pod is scheduled onto nodes that support that runtime.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.