Courseiva
System Hardening →hardMultiple Choice

CKS System Hardening Practice Question

An administrator wants to ensure that containers in a pod cannot run with any Linux capabilities except the minimal required for the container runtime. The pod is subject to the 'restricted' Pod Security Standard. Which capability configuration should be set in the pod's security context?

⚠ Common exam trap

CNCF often tests the misconception that dropping only specific dangerous capabilities (like `NET_RAW` and `CHOWN`) is sufficient for the 'restricted' PSS, when in fact the standard requires dropping all capabilities to achieve the minimal privilege level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

capabilities: drop: ["ALL"]

The 'restricted' Pod Security Standard (PSS) requires that all Linux capabilities be dropped except those essential for the container runtime (e.g., CAP_NET_BIND_SERVICE is allowed by default in some runtimes, but the standard explicitly mandates dropping all capabilities). Option A correctly uses `drop: ["ALL"]` to remove every capability, ensuring the container runs with the minimal set required by the runtime, which aligns with the PSS 'restricted' profile. This approach enforces the principle of least privilege by preventing the container from gaining any unnecessary kernel privileges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    capabilities: drop: ["ALL"]

    Why this is correct

    Dropping ALL is mandatory under the restricted Pod Security Standard. This entry clears every Linux capability from the container's bounding set, so processes start with zero capabilities beyond the default set (which is effectively none). The policy explicitly requires `drop: ["ALL"]` and forbids any `add` entries; this is the only option that fully satisfies that control and is therefore valid.

  • ✗

    capabilities: drop: ["NET_RAW", "CHOWN"]

    Why it's wrong here

    This partial drop list removes only NET_RAW and CHOWN, leaving many other default capabilities such as SETUID, SETGID, and KILL intact. The restricted profile requires that *all* capabilities be dropped, not just a selected few. A policy engine validating against this profile will reject the container because the required `drop: ["ALL"]` entry is absent, regardless of how many individual capabilities are listed.

  • ✗

    capabilities: add: ["NET_BIND_SERVICE"]

    Why it's wrong here

    Adding NET_BIND_SERVICE explicitly grants the container a capability, which is strictly forbidden under the restricted Pod Security Standard. Even though the intent may be to allow binding to a privileged port below 1024, the restricted profile's allowlist does not permit any `add` statements. The only acceptable capability configuration under this profile is `drop: ["ALL"]`; therefore this option fails validation.

  • ✗

    capabilities: add: ["ALL"]

    Why it's wrong here

    Adding ALL grants every Linux capability to the container, effectively giving it privileges comparable to a root process with the full capability bounding set. This is the exact opposite of the restricted profile's requirement to drop all capabilities, and it is explicitly disallowed. Not only does it violate the policy, but it also introduces a severe security risk because containers would gain sensitive capabilities like SYS_ADMIN, NET_ADMIN, and DAC_OVERRIDE.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.