CKS System Hardening Practice Question
An administrator wants to drop all capabilities for a container and then add back only NET_BIND_SERVICE. Which securityContext configuration is correct?
⚠ Common exam trap
Kubernetes often tests the order of operations in capability management — candidates mistakenly think that adding a capability after dropping all is unnecessary or that dropping all alone is sufficient, but the correct sequence must explicitly include both `drop: ["ALL"]` and `add: ["NET_BIND_SERVICE"]` to achieve the intended least-privilege state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
capabilities: drop: ["ALL"] add: ["NET_BIND_SERVICE"]
It first drops all capabilities using `drop: ["ALL"]`, which removes every Linux capability from the container, and then explicitly adds back only `NET_BIND_SERVICE`. This follows the principle of least privilege: start with no capabilities and grant only what is needed. The `securityContext` in Kubernetes applies these settings at the container level, ensuring the container can bind to privileged ports (below 1024) without any other elevated permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
capabilities: add: ["NET_BIND_SERVICE"]
Why it's wrong here
Adding NET_BIND_SERVICE without dropping ALL leaves the container's default capability set intact, so it retains capabilities the stem wants removed. The requirement is default-deny then selective add. Adding a single capability suits containers that need one extra privilege atop the runtime defaults.
- ✗
capabilities: drop: ["ALL"]
Why it's wrong here
Dropping ALL removes every capability, but the stem also requires NET_BIND_SERVICE to be added back. This configuration leaves the container without it, so binding to privileged ports below 1024 fails. Dropping ALL alone suits hardened workloads that need no capabilities whatsoever.
- ✓
capabilities: drop: ["ALL"] add: ["NET_BIND_SERVICE"]
Why this is correct
Dropping "ALL" first strips every Linux capability, including defaults, then adding NET_BIND_SERVICE back grants only the ability to bind ports below 1024. This satisfies the stem's constraint of a single re-added capability, since Kubernetes applies drops before adds within the same securityContext.
- ✗
capabilities: drop: ["NET_BIND_SERVICE"] add: ["ALL"]
Why it's wrong here
This inverts the requirement: it drops NET_BIND_SERVICE and adds ALL, granting the container every capability instead of only the one needed. The stem demands a default-deny posture with a single capability restored. Adding ALL is used when a workload genuinely requires broad privileged access.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.