Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

A security team wants to enforce that containers in a specific namespace cannot gain new capabilities. Which Pod security context field is used to achieve this?

⚠ Common exam trap

The trap is that candidates often choose capabilities.drop: ['ALL'] because it removes all capabilities, but the question asks for preventing containers from gaining new capabilities. allowPrivilegeEscalation: false prevents privilege escalation at runtime, which is the mechanism for gaining new capabilities beyond those initially granted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

allowPrivilegeEscalation: false

`allowPrivilegeEscalation: false` directly controls whether a process can gain more privileges than its parent, which is the mechanism by which containers acquire new capabilities (e.g., via `setuid` binaries or `file capabilities`). Setting this to `false` prevents privilege escalation within the container, effectively blocking the acquisition of new capabilities beyond those initially granted. This field is defined in the Pod Security Context and is a key control for minimizing microservice vulnerabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    capabilities.drop: ["ALL"]

    Why it's wrong here

    Dropping all Linux capabilities via capabilities.drop removes the container's effective, permitted, and inheritable capability sets, but it does not set the no_new_privs attribute. A container process that retains CAP_SETUID or CAP_SETGID (if not dropped? they are dropped, but the running process could acquire them via a file capability or setuid binary) can still escalate; specifically, dropping capabilities does not prevent privilege escalation through setuid executables, file capabilities, or user namespaces. Thus, while it reduces the attack surface, it is not a complete mitigation for privilege escalation.

  • ✗

    privileged: false

    Why it's wrong here

    Setting privileged: false only disables the privileged mode, which would otherwise grant all capabilities and full host access. This is the default Kubernetes state, and it does not enforce any restriction on a process's ability to gain more privileges after startup. Even with privileged: false, a container running as root can use its existing capabilities or exploit a setuid binary to elevate privileges, so it provides no direct control over privilege escalation.

  • ✓

    allowPrivilegeEscalation: false

    Why this is correct

    The setting allowPrivilegeEscalation: false is specifically designed to prevent privilege escalation by setting the no_new_privs process attribute (or equivalent) on the container's main process. When enabled, this Linux security feature blocks any execution that would result in a privilege gain, including setuid/setgid binaries, file capabilities, and other mechanisms that could elevate the process's UID or GID. It is the sole option among these that directly addresses the privileged escalation vector, making it the correct control for the security team's requirement.

  • ✗

    runAsNonRoot: true

    Why it's wrong here

    Setting runAsNonRoot: true enforces that the container's primary process runs with a non-zero UID, but it does not prevent that non-root process from subsequently gaining higher privileges. The process could still execute a setuid binary (e.g., su or sudo) if filesystem permissions allow, and it could acquire additional Linux capabilities through file capabilities or other means. Thus, this option only controls the initial user ID, not the ability to escalate, so it is insufficient for the stated goal.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.