Courseiva
Cluster Hardening →easyMultiple Choice

CKS Cluster Hardening Practice Question

An administrator wants to prevent pods from running as root. Which SecurityContext field should be set at the pod level?

⚠ Common exam trap

CNCF often tests the distinction between setting a specific user ID (runAsUser) and enforcing a non-root requirement (runAsNonRoot), where candidates mistakenly think that setting runAsUser to a non-zero value alone prevents root execution, but it does not block an image that runs as root by default if runAsUser is omitted or set to 0.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

runAsNonRoot: true

Setting `runAsNonRoot: true` at the pod-level SecurityContext enforces that all containers in the pod must run with a non-root user (UID > 0). If a container image specifies a user with UID 0 (root) or does not specify a user, the container will fail to start, preventing privilege escalation from root access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    fsGroup: 2000

    Why it's wrong here

    The fsGroup field controls the group ownership assigned to mounted volumes, not the identity of the container's primary process. A pod can still run with UID 0 while fsGroup is set, so it does not satisfy the requirement to prevent root execution. It only affects how files and directories on volumes are group-readable/writable, leaving the process user unchanged.

  • ✗

    runAsGroup: 3000

    Why it's wrong here

    Setting runAsGroup only overrides the primary group ID (GID) of the container's processes; the user ID (UID) remains whatever the image and runAsUser define. If runAsUser is absent, the image's default user is often root (UID 0), so the process still runs as root. Thus runAsGroup alone cannot guarantee a non-root execution context.

  • ✗

    runAsUser: 1000

    Why it's wrong here

    While runAsUser can set a non-zero UID, it is merely a specific user assignment and does not inherently enforce a non-root policy. If omitted or set to 0, the container runs as root; even a value like 1000 only works if it matches the desired security constraint and the image supports that user. Since the goal is to prevent root, this field must be explicitly combined with runAsNonRoot or set to a non-zero value, making it an indirect and error-prone control.

  • ✓

    runAsNonRoot: true

    Why this is correct

    When set to true, this securityContext field enforces at admission and runtime that the container's UID is non-zero. If the image's configured user or an explicit runAsUser is 0, Kubernetes will refuse to start the pod, producing a CreateContainerConfigError or validation failure. This directly meets the requirement to prevent pods from running as root, making it the correct choice.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A pod is failing to start with: 'Error: container has runAsNonRoot and image will run as root'. The pod spec sets securityContext.runAsNonRoot: true. The container image is 'nginx:latest' which runs as root. Which change allows the pod to run while maintaining security?

hard
  • A.Remove runAsNonRoot: true
  • B.Add a PodSecurityPolicy that allows root
  • ✓ C.Set runAsUser: 1000 in the container securityContext
  • D.Use a mutating webhook to change the image

Why C: Setting `runAsUser: 1000` in the container's securityContext overrides the default user (root) in the image, ensuring the container process runs as a non-root user (UID 1000). This satisfies the `runAsNonRoot: true` constraint at the pod level, which requires that the container's user ID is non-zero, while still maintaining security by not running as root.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.