CKS Minimize Microservice Vulnerabilities Practice Question
A security admin wants to ensure all pods in a cluster drop ALL Linux capabilities. Which of the following YAML snippets should be added to a PodSecurityPolicy (assuming PSP is enabled) or a pod spec?
⚠ Common exam trap
Many candidates confuse the YAML syntax for dropping capabilities (must be a list) with a string value, or they think dropping a single capability like NET_RAW is sufficient to remove all capabilities. Also, note that PodSecurityPolicy is deprecated in Kubernetes 1.21 and removed in 1.25, so for newer clusters, use Pod Security Admission or a pod security context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
capabilities: drop: ["ALL"]
Dropping all Linux capabilities from a container is achieved by specifying `drop: ["ALL"]` in the PodSecurityPolicy or pod security context. This ensures the container runs with no capabilities, following the principle of least privilege. The correct syntax uses a YAML list (array) for the `drop` field, not a string.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
capabilities: drop: "ALL"
Why it's wrong here
The `capabilities.drop` field in a Kubernetes `securityContext` is a typed list of strings; a quoted scalar like `"ALL"` is not a valid YAML sequence and fails the API schema validation. Even though the intent is to drop everything, the pod will be rejected before the container runtime ever applies any capability settings. To drop all capabilities you must supply a YAML list, e.g. `drop: ["ALL"]`.
- ✗
capabilities: drop: - "NET_RAW"
Why it's wrong here
Listing only `NET_RAW` removes the CAP_NET_RAW capability, which affects raw sockets and packet crafting, but every other Linux capability granted by the runtime—such as `CHOWN`, `DAC_OVERRIDE`, `FOWNER`, `SETUID`, and `SETGID`—remains enabled. This narrow hardening does not satisfy the requirement to drop all capabilities and still leaves the container with default abilities to change file ownership, bypass file permissions, or change process UIDs. Only `drop: ["ALL"]` clears the entire default capability set.
- ✗
capabilities: add: ["ALL"]
Why it's wrong here
The `add` field is an additive capability list; `add: ["ALL"]` attempts to grant every Linux capability to the container, including powerful ones like `CAP_SYS_ADMIN`, `CAP_SYS_PTRACE`, and `CAP_NET_ADMIN`, which is the exact opposite of dropping capabilities. This configuration weakens isolation and would likely violate Pod Security Standards, whereas the requirement is to reduce the privilege surface. To meet the stated goal, `add` must not be used with `ALL`; the correct action is to remove capabilities via `drop`.
- ✓
capabilities: drop: ["ALL"]
Why this is correct
Setting `capabilities.drop: ["ALL"]` inside the `securityContext` removes every Linux capability from the container's capability sets, leaving the process with no capabilities beyond those required for basic operation. This is a security best practice because it prevents many privilege-escalation attacks, including those that abuse a setuid binary or a capability retained by the runtime. The list form is mandatory; Kubernetes validates `drop` as an array of capability names, and `ALL` is the wildcard that clears the entire default set.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.