CKS System Hardening Practice Question
An administrator creates a custom seccomp profile and wants to apply it to a pod. The profile file is named 'audit.json' and is placed in the default seccomp directory on the node. Which securityContext field should be used?
⚠ Common exam trap
The CKS exam often tests the distinction between the deprecated annotation-based approach and the current `securityContext.seccompProfile` fields, and the trap here is that candidates confuse the field name `localhostProfile` with `file` or `profile`, or mistakenly think the annotation is still the standard method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
securityContext.seccompProfile.type: Localhost and securityContext.seccompProfile.localhostProfile: audit.json
In Kubernetes, when using a custom seccomp profile stored on the node's default seccomp directory, the `securityContext.seccompProfile.type` must be set to `Localhost` and the profile filename is specified via the `localhostProfile` field. This field expects the filename (e.g., `audit.json`) relative to the node's default seccomp path (`/var/lib/kubelet/seccomp`). The `type: Localhost` instructs kubelet to load the profile from the node's filesystem.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
securityContext.seccompProfile.type: Localhost and securityContext.seccompProfile.file: audit.json
Why it's wrong here
The seccompProfile object exposes exactly three fields: type, localhostProfile, and (indirectly) the Windows profile fields; 'file' is not a recognized key. Using an invalid field name causes the Pod manifest to fail API validation, so the profile would never be applied. The correct way to reference a custom profile on the node is to set type: Localhost and provide the file name via localhostProfile.
- ✗
securityContext.seccompProfile.type: Localhost and securityContext.seccompProfile.profile: audit.json
Why it's wrong here
While the field name 'profile' might seem intuitive, Kubernetes does not define a 'profile' key under securityContext.seccompProfile. The only field that takes the custom profile's file path is localhostProfile; anything else is ignored or rejected by the API server. Choosing 'profile' would not configure the seccomp filter, and the Pod would run without the intended restriction.
- ✓
securityContext.seccompProfile.type: Localhost and securityContext.seccompProfile.localhostProfile: audit.json
Why this is correct
This is the correct syntax in v1.29 and later: type: Localhost tells the kubelet to load a profile from the node's seccomp profile directory, and localhostProfile: audit.json specifies the exact file name. The file must be present on the node under the kubelet's seccomp root (commonly /var/lib/kubelet/seccomp) before the Pod can start. This field was added to replace the old annotation, and it is the stable, validated API for custom profiles.
- ✗
seccomp.security.alpha.kubernetes.io/pod: localhost/audit.json
Why it's wrong here
The annotation seccomp.security.alpha.kubernetes.io/pod is the original pre-GA mechanism and has been deprecated for several releases; in v1.29 it is ignored and produces a warning. Unlike the structured seccompProfile field, the annotation uses a single string in the format 'localhost/audit.json', and it is not part of the Pod's spec but a non-standard annotation. To use the custom profile you must move to the securityContext.seccompProfile field, which is the only version that is guaranteed to work in modern clusters.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.