CKS Minimize Microservice Vulnerabilities Practice Question
A security policy requires that all pods drop ALL Linux capabilities and disable privilege escalation. Which YAML snippet correctly implements this in the pod's security context?
⚠ Common exam trap
A common Kubernetes exam trap is the distinction between `privileged: false` (which does not drop capabilities) and explicitly dropping capabilities with `drop: ["ALL"]`, leading candidates to mistakenly think setting `privileged: false` is sufficient to remove all capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
securityContext: allowPrivilegeEscalation: false capabilities: drop: ["ALL"]
It explicitly drops all Linux capabilities with `capabilities: drop: ["ALL"]` and disables privilege escalation with `allowPrivilegeEscalation: false`. This satisfies the security policy requirement to remove all capabilities and prevent any process from gaining more privileges than its parent, which is essential for minimizing container breakout risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
securityContext: privileged: false capabilities: drop: ["ALL"]
Why it's wrong here
Although dropping ALL capabilities is a strong move, setting privileged: false alone does not enforce allowPrivilegeEscalation: false. In Kubernetes, privileged: false is merely the default and does not prevent a process from using setuid binaries or other privilege escalation mechanisms to gain additional privileges. Since the policy requires both dropping all capabilities and preventing privilege escalation, this pod still violates the least-privilege requirement.
- ✗
securityContext: allowPrivilegeEscalation: false capabilities: add: ["NET_ADMIN"]
Why it's wrong here
This configuration explicitly adds NET_ADMIN, a highly privileged capability that grants broad control over network interfaces, routing tables, and firewall rules (e.g., iptables). Adding any capability contradicts the policy requirement to drop ALL Linux capabilities, as it reintroduces powerful permissions that a compromised process could abuse. Even with allowPrivilegeEscalation: false, the container retains NET_ADMIN, directly violating the security policy's intent.
- ✗
securityContext: capabilities: drop: ["ALL"]
Why it's wrong here
Dropping ALL capabilities correctly removes every Linux capability from the container, but the absence of allowPrivilegeEscalation: false leaves a serious loophole. Without that flag, a process can still escalate privileges by executing setuid-root programs or leveraging file capabilities, even if the container initially has no capabilities. The policy explicitly requires privilege escalation to be disabled, so this incomplete configuration fails the security requirement.
- ✓
securityContext: allowPrivilegeEscalation: false capabilities: drop: ["ALL"]
Why this is correct
This security context satisfies the policy by combining two essential controls: capabilities.drop: ["ALL"] removes every Linux capability from the container's effective/permitted sets, and allowPrivilegeEscalation: false prevents any process from gaining additional privileges via setuid, file capabilities, or other escalation paths. Together they enforce a strict least-privilege environment where even a compromised process cannot elevate its rights. This is the canonical way to run a truly unprivileged pod in Kubernetes.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.