Courseiva
System Hardening →hardMultiple Choice

CKS System Hardening Practice Question

A pod is using a custom seccomp profile stored at /var/lib/kubelet/seccomp/custom-profile.json. Which securityContext configuration correctly references this profile?

⚠ Common exam trap

The CKS exam often tests the misconception that `localhostProfile` requires an absolute path, but the correct syntax is a relative path (just the filename) when the profile resides in the default kubelet seccomp directory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

seccompProfile: type: Localhost localhostProfile: "custom-profile.json"

When using a custom seccomp profile stored in the default kubelet seccomp directory (`/var/lib/kubelet/seccomp/`), the `type` must be `Localhost` and the `localhostProfile` must be a relative path (just the filename). Kubernetes automatically prepends the default seccomp root path, so `custom-profile.json` resolves to `/var/lib/kubelet/seccomp/custom-profile.json`.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    seccompProfile: type: Unconfined localhostProfile: "custom-profile.json"

    Why it's wrong here

    With type: Unconfined, the container runtime deliberately applies no seccomp filter, leaving the container's syscalls unrestricted. The localhostProfile field is only honored when type is Localhost; setting it alongside Unconfined is contradictory and the API server rejects the combination because a custom profile cannot be loaded when seccomp is explicitly disabled.

  • ✗

    seccompProfile: type: RuntimeDefault localhostProfile: "custom-profile.json"

    Why it's wrong here

    RuntimeDefault instructs the runtime to use its own preconfigured seccomp profile (for example, the default profile shipped with containerd or Docker). Since the runtime's default profile is built in, there is no need for a custom file path, and Kubernetes validation requires that localhostProfile be omitted unless type is Localhost, so this combination will be rejected.

  • ✗

    seccompProfile: type: Localhost localhostProfile: "/var/lib/kubelet/seccomp/custom-profile.json"

    Why it's wrong here

    Even with the correct type, localhostProfile must be just the filename, such as custom-profile.json, not an absolute path. The kubelet resolves this name relative to its seccomp root directory (usually /var/lib/kubelet/seccomp), so passing /var/lib/kubelet/seccomp/custom-profile.json causes the kubelet to look for a file named var/lib/kubelet/seccomp/custom-profile.json inside that directory, resulting in a profile-loading error.

  • ✓

    seccompProfile: type: Localhost localhostProfile: "custom-profile.json"

    Why this is correct

    This is the correct configuration: type Localhost tells the kubelet to load a custom seccomp profile from a file on the node, and localhostProfile gives the filename relative to the kubelet's seccomp directory. The kubelet then constructs the full path /var/lib/kubelet/seccomp/custom-profile.json and passes it to the container runtime, which enforces the syscall restrictions defined in that JSON file.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.