Courseiva
System Hardening →mediumMultiple Choice

CKS System Hardening Practice Question

An administrator needs to apply a seccomp profile to a Pod. The profile is defined in a file named audit.json located on each node at /var/lib/kubelet/seccomp/profiles/audit.json. The cluster is running Kubernetes 1.25. Which seccomp type should be used in the Pod's securityContext to reference this profile?

⚠ Common exam trap

The trap here is assuming that RuntimeDefault can be customized with a file path; only Localhost supports referencing a profile file on the node.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Localhost

To use a custom seccomp profile stored on the node, the seccomp type must be set to Localhost, and the localhostProfile field must specify the path relative to the kubelet's seccomp root directory. RuntimeDefault uses a predefined profile, Unconfined disables seccomp, and DockerDefault is not a valid Kubernetes seccomp type. Therefore, Localhost is the correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Localhost

    Why this is correct

    The Localhost seccomp type allows referencing a profile file that resides on the node's filesystem. The path is relative to the kubelet's seccomp profile root directory, typically /var/lib/kubelet/seccomp. Given the file at /var/lib/kubelet/seccomp/profiles/audit.json, the correct localhostProfile value would be profiles/audit.json, and the type must be Localhost.

  • ✗

    Unconfined

    Why it's wrong here

    Unconfined disables seccomp filtering entirely, which is the opposite of applying a restrictive profile. It does not reference any profile file and would leave the container with no seccomp restrictions. This is not appropriate when the goal is to enforce a custom seccomp profile.

  • ✗

    RuntimeDefault

    Why it's wrong here

    RuntimeDefault uses the container runtime's default seccomp profile, which is predefined and not customizable per Pod. It does not allow specifying a custom profile file on the node. Since the requirement is to use a specific profile file named audit.json, RuntimeDefault cannot satisfy it.

  • ✗

    DockerDefault

    Why it's wrong here

    DockerDefault is not a valid seccomp type in Kubernetes. The supported types are Localhost, RuntimeDefault, and Unconfined. Using an invalid type would cause the Pod to be rejected. Even if it existed, it would not reference a custom profile file on the node.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.