CKS System Hardening Practice Question
An administrator needs to apply a seccomp profile to a Pod. The profile is defined in a file named audit.json located on each node at /var/lib/kubelet/seccomp/profiles/audit.json. The cluster is running Kubernetes 1.25. Which seccomp type should be used in the Pod's securityContext to reference this profile?
⚠ Common exam trap
The trap here is assuming that RuntimeDefault can be customized with a file path; only Localhost supports referencing a profile file on the node.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Localhost
To use a custom seccomp profile stored on the node, the seccomp type must be set to Localhost, and the localhostProfile field must specify the path relative to the kubelet's seccomp root directory. RuntimeDefault uses a predefined profile, Unconfined disables seccomp, and DockerDefault is not a valid Kubernetes seccomp type. Therefore, Localhost is the correct choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Localhost
Why this is correct
The Localhost seccomp type allows referencing a profile file that resides on the node's filesystem. The path is relative to the kubelet's seccomp profile root directory, typically /var/lib/kubelet/seccomp. Given the file at /var/lib/kubelet/seccomp/profiles/audit.json, the correct localhostProfile value would be profiles/audit.json, and the type must be Localhost.
- ✗
Unconfined
Why it's wrong here
Unconfined disables seccomp filtering entirely, which is the opposite of applying a restrictive profile. It does not reference any profile file and would leave the container with no seccomp restrictions. This is not appropriate when the goal is to enforce a custom seccomp profile.
- ✗
RuntimeDefault
Why it's wrong here
RuntimeDefault uses the container runtime's default seccomp profile, which is predefined and not customizable per Pod. It does not allow specifying a custom profile file on the node. Since the requirement is to use a specific profile file named audit.json, RuntimeDefault cannot satisfy it.
- ✗
DockerDefault
Why it's wrong here
DockerDefault is not a valid seccomp type in Kubernetes. The supported types are Localhost, RuntimeDefault, and Unconfined. Using an invalid type would cause the Pod to be rejected. Even if it existed, it would not reference a custom profile file on the node.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.