Courseiva
System Hardening →mediumMultiple Choice

CKS System Hardening Practice Question

A pod is running with a custom seccomp profile located at /var/lib/kubelet/seccomp/my-profile.json. Which securityContext configuration correctly applies this profile?

⚠ Common exam trap

The trap here is that candidates mistakenly provide the full absolute path in `localhostProfile`, not realizing that Kubernetes automatically prepends the default seccomp directory, leading to a double-path error.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

seccompProfile: { type: Localhost, localhostProfile: my-profile.json }

When using a custom seccomp profile stored on the node, the `type` must be `Localhost` and the `localhostProfile` field must specify only the filename (not the full path). Kubernetes automatically prepends the default seccomp profile path `/var/lib/kubelet/seccomp/` to the `localhostProfile` value, so `my-profile.json` resolves to the correct location.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    seccompProfile: { type: RuntimeDefault }

    Why it's wrong here

    seccompProfile: { type: RuntimeDefault } does not load any custom profile. This option instructs the container runtime to apply its own default seccomp profile (for example, Docker's default or containerd's), which is a generic security baseline and cannot be tailored to the specific syscalls your application needs. Since a custom profile file already exists on the node, choosing RuntimeDefault means that file is never read, so the intended restrictions are not enforced.

  • ✓

    seccompProfile: { type: Localhost, localhostProfile: my-profile.json }

    Why this is correct

    seccompProfile: { type: Localhost, localhostProfile: my-profile.json } is correct because Localhost explicitly tells Kubernetes to load a seccomp profile from a file on the node, and localhostProfile names that file relative to the kubelet's seccomp root directory, which defaults to /var/lib/kubelet/seccomp/. As long as my-profile.json is placed in that directory, Kubernetes constructs the absolute path /var/lib/kubelet/seccomp/my-profile.json and applies it to the container. This is the intended way to reference a custom profile, and the exact filename must match the file that exists on the node.

  • ✗

    seccompProfile: { type: Localhost, localhostProfile: /var/lib/kubelet/seccomp/my-profile.json }

    Why it's wrong here

    seccompProfile: { type: Localhost, localhostProfile: /var/lib/kubelet/seccomp/my-profile.json } is wrong because localhostProfile must be a path relative to the kubelet's seccomp root, not an absolute path. Kubernetes joins localhostProfile to the configured seccomp root (normally /var/lib/kubelet/seccomp), so specifying an absolute path results in an incorrectly concatenated location such as /var/lib/kubelet/seccomp/var/lib/kubelet/seccomp/my-profile.json, causing the profile to be not found. The correct value is the relative filename my-profile.json, letting Kubernetes resolve it against the proper base directory.

  • ✗

    seccompProfile: { type: Unconfined }

    Why it's wrong here

    seccompProfile: { type: Unconfined } disables seccomp entirely for the container, which means no syscall filtering is applied and the container can issue any syscall permitted by the other security layers (like capabilities). This option neither uses a custom profile nor applies the runtime's default profile, so it is the least secure choice and would completely bypass the protections that the custom profile was designed to enforce. It is never appropriate when a custom seccomp profile has been provisioned.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.