CKS System Hardening Practice Question
An administrator wants to ensure that containers in a pod cannot run with any Linux capabilities except the minimal required for the container runtime. The pod is subject to the 'restricted' Pod Security Standard. Which capability configuration should be set in the pod's security context?
⚠ Common exam trap
CNCF often tests the misconception that dropping only specific dangerous capabilities (like `NET_RAW` and `CHOWN`) is sufficient for the 'restricted' PSS, when in fact the standard requires dropping all capabilities to achieve the minimal privilege level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
capabilities: drop: ["ALL"]
The 'restricted' Pod Security Standard (PSS) requires that all Linux capabilities be dropped except those essential for the container runtime (e.g., CAP_NET_BIND_SERVICE is allowed by default in some runtimes, but the standard explicitly mandates dropping all capabilities). Option A correctly uses `drop: ["ALL"]` to remove every capability, ensuring the container runs with the minimal set required by the runtime, which aligns with the PSS 'restricted' profile. This approach enforces the principle of least privilege by preventing the container from gaining any unnecessary kernel privileges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
capabilities: drop: ["ALL"]
Why this is correct
Dropping ALL is mandatory under the restricted Pod Security Standard. This entry clears every Linux capability from the container's bounding set, so processes start with zero capabilities beyond the default set (which is effectively none). The policy explicitly requires `drop: ["ALL"]` and forbids any `add` entries; this is the only option that fully satisfies that control and is therefore valid.
- ✗
capabilities: drop: ["NET_RAW", "CHOWN"]
Why it's wrong here
This partial drop list removes only NET_RAW and CHOWN, leaving many other default capabilities such as SETUID, SETGID, and KILL intact. The restricted profile requires that *all* capabilities be dropped, not just a selected few. A policy engine validating against this profile will reject the container because the required `drop: ["ALL"]` entry is absent, regardless of how many individual capabilities are listed.
- ✗
capabilities: add: ["NET_BIND_SERVICE"]
Why it's wrong here
Adding NET_BIND_SERVICE explicitly grants the container a capability, which is strictly forbidden under the restricted Pod Security Standard. Even though the intent may be to allow binding to a privileged port below 1024, the restricted profile's allowlist does not permit any `add` statements. The only acceptable capability configuration under this profile is `drop: ["ALL"]`; therefore this option fails validation.
- ✗
capabilities: add: ["ALL"]
Why it's wrong here
Adding ALL grants every Linux capability to the container, effectively giving it privileges comparable to a root process with the full capability bounding set. This is the exact opposite of the restricted profile's requirement to drop all capabilities, and it is explicitly disallowed. Not only does it violate the policy, but it also introduces a severe security risk because containers would gain sensitive capabilities like SYS_ADMIN, NET_ADMIN, and DAC_OVERRIDE.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.