CKS Monitoring, Logging and Runtime Security Practice Question
A pod runs with an immutable root filesystem (readOnlyRootFilesystem: true). The application attempts to write to /tmp. What is the expected behavior?
⚠ Common exam trap
In the CKS exam, a common pitfall is assuming that /tmp is inherently writable or that the container will crash. The correct understanding is that the kernel enforces the read-only flag at the filesystem level, and writes fail with a permission error unless a writable volume is mounted at /tmp.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The write fails with a permission error unless a writable volume is mounted at /tmp
When a pod is configured with `readOnlyRootFilesystem: true`, the container's root filesystem is mounted as read-only. The `/tmp` directory is part of the root filesystem, so any write attempt to it will fail with a permission error (EPERM) unless a writable volume (e.g., `emptyDir`, `hostPath`, or `PersistentVolumeClaim`) is explicitly mounted at `/tmp`. This is enforced by the Linux kernel's mount flags and is a common security hardening practice to prevent unauthorized writes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The write fails with a permission error unless a writable volume is mounted at /tmp
Why this is correct
The write fails because `securityContext.readOnlyRootFilesystem: true` makes the container's root filesystem read-only at the kernel level, so every path on the root filesystem—including /tmp—is immutable. The `write()` syscall returns `EROFS` (read-only file system) or `EACCES` (permission denied) unless a writable volume such as an `emptyDir` is explicitly mounted at /tmp. The error is surfaced to the application, not hidden.
- ✗
The application can write to any directory because /tmp is always writable
Why it's wrong here
This is incorrect because `readOnlyRootFilesystem` applies to the entire root filesystem, not just selected directories. The statement that /tmp is "always writable" is a common misconception: by default, containers run with a writable layer, but setting `readOnlyRootFilesystem: true` removes that writability for all paths on the root filesystem. A write to /tmp will succeed only if you mount a separate writable volume at that mount point, overriding the read-only restriction locally.
- ✗
The container crashes immediately
Why it's wrong here
The container does not crash immediately because the read-only enforcement happens at the syscall boundary, not at startup. The container process starts normally and executes code until it attempts to write to the root filesystem. Many applications only write after startup, so the failure appears later. If the app does not handle the write error gracefully, it may crash at that later point, but there is no intrinsic immediate crash from the read-only root alone.
- ✗
The write succeeds and is silently dropped
Why it's wrong here
The write does not succeed and get silently dropped; the kernel rejects it definitively. When the application calls `write()`, the filesystem returns an error (`EROFS` or `EPERM`), so the data is never written. The call fails, and the application receives an error return code. A silent drop would require the write to appear successful, which is impossible with a read-only mount—there is no hidden buffer or ephemeral store that accepts and discards the data.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.