CKS System Hardening Practice Question
An administrator wants to run a container that requires the SYS_TIME capability. Which field should be used in the securityContext to add this capability?
⚠ Common exam trap
It's easy for candidates to confuse `privileged: true` (which grants all capabilities but is overly permissive) with the more precise `capabilities.add` approach, or they mistakenly think `allowPrivilegeEscalation` is related to adding capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
capabilities.add
The `capabilities.add` field in the `securityContext` is specifically designed to add Linux capabilities (such as `SYS_TIME`) to a container without granting full root privileges. This follows the principle of least privilege, allowing only the required capability to modify the system clock.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
capabilities.add
Why this is correct
The `capabilities.add` field in a container's securityContext is the precise mechanism for granting individual Linux capabilities, such as NET_ADMIN or SYS_TIME, to a specific container without affecting the host or other containers. By explicitly adding only the required capabilities, the container runs with the least privilege necessary, adhering to the principle of least privilege. This field accepts a list of capability names, which are then unioned with the default capability set of the container runtime.
- ✗
privileged: true
Why it's wrong here
Setting `privileged: true` runs the container with all capabilities and disables all security features enforced by the container runtime, effectively giving the container near-host-level access. While this might technically satisfy the requirement of adding capabilities, it is far too broad and insecure because it grants every possible capability and lifts restrictions like seccomp and AppArmor, which is almost never appropriate for a single specific capability. This approach is the anti-pattern of least privilege and is generally reserved for special system-level containers that absolutely need full host access.
- ✗
allowPrivilegeEscalation: true
Why it's wrong here
`allowPrivilegeEscalation: true` controls whether a process can gain more privileges than its parent, typically through setuid binaries or file capabilities, but it does not itself add any capabilities to the container. This boolean flag, when true, permits the container's processes to escalate privileges, but it does not define which capabilities are available—that is the job of the capabilities field. Therefore, this setting alone cannot satisfy the requirement of adding a specific capability, as it merely removes a safety barrier without granting any concrete Linux capability.
- ✗
capabilities.drop
Why it's wrong here
The `capabilities.drop` field is the inverse of `capabilities.add`—it removes capabilities from the container's effective, permitted, and inheritable sets. While dropping capabilities is a recommended security hardening practice, it cannot add capabilities that the container needs. If an administrator needs to grant a specific capability, they must use `capabilities.add`; using `capabilities.drop` would only take capabilities away, potentially causing the container to fail if it requires elevated privileges that were already present in the default set.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.