CKS System Hardening Practice Question
An admin runs 'kubectl describe pod secure-pod' and sees 'seccompProfile: RuntimeDefault' under the container's security context. Which seccomp profile is being used?
⚠ Common exam trap
Watch out — candidates often confuse `RuntimeDefault` with a custom profile stored on the node's filesystem, or mistakenly think it disables seccomp entirely, when in fact it instructs the runtime to apply its own pre-configured default seccomp filter.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The container runtime's default seccomp profile is applied
When `seccompProfile` is set to `RuntimeDefault` in a container's security context, Kubernetes instructs the container runtime (e.g., containerd, CRI-O) to apply its own default seccomp profile. This profile is typically a restrictive set of syscalls that blocks dangerous or unnecessary system calls while allowing common operations. It is not a custom profile from the node's filesystem, nor does it disable seccomp or set it to unconfined.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A custom seccomp profile from '/var/lib/kubelet/seccomp/' is used
Why it's wrong here
A custom seccomp profile from '/var/lib/kubelet/seccomp/' would be referenced via `seccompProfile.type: Localhost` and a `localhostProfile` field pointing to that file, not via `RuntimeDefault`. The value `RuntimeDefault` is a built-in selector that tells the container runtime to apply its own compiled-in default profile, so no filesystem path is consulted. Because the describe output indicates `RuntimeDefault`, no profile from the kubelet's seccomp directory is loaded.
- ✓
The container runtime's default seccomp profile is applied
Why this is correct
When the pod's seccomp profile is set to `RuntimeDefault`, the container runtime (e.g., containerd or CRI-O) applies its own default seccomp filter, which restricts a known set of dangerous or unnecessary system calls while still allowing normal container operations. This is a deliberate security configuration that enables seccomp enforcement without requiring an operator to craft and distribute a custom profile. It is the recommended baseline for secure pods because it blocks a larger attack surface than leaving seccomp unconfined.
- ✗
The container runtime's seccomp profile is set to 'Unconfined'
Why it's wrong here
`RuntimeDefault` is not equivalent to `Unconfined`; these two values are semantically opposite. `Unconfined` disables seccomp entirely, permitting every system call the container process makes, whereas `RuntimeDefault` installs a curated deny-list of syscalls that the runtime maintains. Thus, seeing `RuntimeDefault` in the describe output proves that the container is running with a restrictive seccomp filter, not an open one.
- ✗
Seccomp is disabled for this container
Why it's wrong here
Seccomp being disabled would be represented by the value `Unconfined`, which means no seccomp filter is applied to the container. The `RuntimeDefault` setting, in contrast, explicitly enables seccomp by instructing the runtime to load its default profile. Therefore, the claim that seccomp is disabled is incorrect; the pod is actively enforcing a runtime-defined seccomp policy, which is a security feature, not an omission.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.