Courseiva
System Hardening →mediumMultiple Choice

CKS System Hardening Practice Question

A pod has the following security context: capabilities: { drop: ['ALL'] } and privileged: false. The pod fails to start because it requires the ability to run iptables commands. Which of the following should be added to the pod's security context?

⚠ Common exam trap

Many candidates confuse SYS_ADMIN with NET_ADMIN, assuming that broad system administration privileges are needed for network tools, when in fact iptables specifically requires the NET_ADMIN capability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

capabilities: { add: ['NET_ADMIN'] }

The pod needs to run iptables commands, which require the NET_ADMIN capability. Since the security context drops ALL capabilities, you must explicitly add NET_ADMIN back. Option D correctly adds NET_ADMIN, granting the necessary network administration privileges without making the container fully privileged.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    privileged: true

    Why it's wrong here

    privileged: true grants the container all Linux capabilities and disables most security mechanisms such as seccomp, AppArmor, and SELinux, making it equivalent to running as root on the host. This is wildly excessive for iptables, which only needs a single capability. It violates the principle of least privilege and dramatically expands the attack surface, potentially allowing container escape.

  • ✗

    capabilities: { add: ['SYS_ADMIN'] }

    Why it's wrong here

    Adding SYS_ADMIN grants a broad set of administrative operations, including mounting filesystems, changing hostnames, and manipulating namespaces. iptables does not require these powers; it specifically needs NET_ADMIN to interact with netfilter. SYS_ADMIN is a notoriously dangerous capability that is frequently exploited to break out of containers, so it is both overprivileged and risky for this use case.

  • ✗

    capabilities: { drop: ['NET_ADMIN'] }

    Why it's wrong here

    Dropping NET_ADMIN actively removes the exact capability that iptables requires to create, modify, and delete netfilter rules. Without NET_ADMIN, the pod will fail with permission errors when trying to run iptables commands. This is the opposite of the needed configuration—instead of helping, it makes the intended task impossible.

  • ✓

    capabilities: { add: ['NET_ADMIN'] }

    Why this is correct

    Adding NET_ADMIN grants precisely the capability required for iptables operations, as it allows control over network administration tasks such as netfilter rules, routing tables, and socket attributes. This is the minimal privilege needed to accomplish the goal, following the least-privilege principle. It is the correct choice because it grants the necessary power without exposing the container to the broader risks associated with privileged mode or SYS_ADMIN.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.