CKS Supply Chain Security Practice Question
A developer wants to create a Deployment that runs as a non-root user. Which YAML snippet correctly sets the security context to run the container with UID 1000?
⚠ Common exam trap
Candidates often confuse `runAsUser` (sets the UID) with `runAsGroup` (sets the GID) or with `runAsNonRoot: true` (which only ensures the container does not run as root, but does not set a specific UID). The question explicitly asks to run with UID 1000, so `runAsUser: 1000` is required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
spec.containers[].securityContext.runAsUser: 1000
`securityContext.runAsUser: 1000` explicitly sets the container's user ID to 1000, ensuring the container process runs as a non-root user. This is the direct way to enforce a specific UID in Kubernetes, meeting the developer's requirement to run as a non-root user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
spec.containers[].securityContext.runAsUser: 0
Why it's wrong here
Setting runAsUser: 0 explicitly assigns UID 0, which is the root user inside the container. Root has unrestricted privileges within the container, so this directly contradicts the developer's requirement to run as a non-root user. Even if the image's default user is non-root, this setting overrides it and grants root access, which is a security risk.
- ✗
spec.containers[].securityContext.runAsNonRoot: true
Why it's wrong here
The runAsNonRoot: true field is an assertion that the container will run as a non-root user, not a declaration of which user to use. It relies on the image having a non-root user configured; if the image's default user is root or unspecified, the container will fail to start instead of falling back to a safe UID. To guarantee running as a non-root user, you must explicitly set runAsUser to a non-zero value.
- ✗
spec.containers[].securityContext.runAsGroup: 1000
Why it's wrong here
runAsGroup: 1000 configures the primary group ID (GID) for the container's processes, not the user ID. This does not affect which user the process runs as, so if the image defaults to root (UID 0), the process remains root regardless of the group. A non-zero group alone does not satisfy the requirement for a non-root user; it must be paired with runAsUser.
- ✓
spec.containers[].securityContext.runAsUser: 1000
Why this is correct
Setting spec.containers[].securityContext.runAsUser: 1000 explicitly forces the container's main process to run with UID 1000, which is a standard non-root user. This overrides any default user in the image and ensures the process is not run as root. It is the direct, concrete way to satisfy the developer's requirement, and it also works in conjunction with pod-level settings.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.