Courseiva
System Hardening →easyMultiple Choice

CKS System Hardening Practice Question

To reduce the attack surface, a security best practice is to drop all capabilities from a container and add only those required. Which securityContext field is used to drop all capabilities?

⚠ Common exam trap

CNCF often tests the exact Kubernetes API field name `capabilities.drop` versus common but incorrect synonyms like `disable` or `remove`, and candidates may confuse dropping all capabilities with simply disabling privileged mode.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

capabilities.drop: ["ALL"]

In Kubernetes, the `capabilities.drop` field in the securityContext is used to explicitly remove Linux capabilities from a container. Setting `capabilities.drop: ["ALL"]` drops all capabilities, effectively reducing the attack surface by ensuring the container starts with no privileges, and then specific capabilities can be added back via `capabilities.add` if needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    capabilities.disable: ["ALL"]

    Why it's wrong here

    The key `capabilities.disable` does not exist in the Kubernetes PodSecurityContext or in the OCI runtime configuration; Linux capabilities are managed with `add` and `drop` fields. A Kubernetes API server would reject this field during schema validation (or it would be silently ignored in older versions), so it performs no action. Therefore it cannot reduce the container's attack surface at all.

  • ✗

    capabilities.remove: ["ALL"]

    Why it's wrong here

    There is no `remove` key under `securityContext.capabilities`; the only supported operations are `add` and `drop`, with `drop` being the list of capabilities to remove after container start. If you attempt to use `capabilities.remove`, the container creation will fail validation or the field will be ignored, leaving every default capability intact. Unlike Docker's `cap_drop`, Kubernetes uses the verb `drop`, so this option does not lower privileges.

  • ✓

    capabilities.drop: ["ALL"]

    Why this is correct

    Setting `capabilities.drop: ["ALL"]` explicitly removes every Linux capability from the container's effective, permitted, and inheritable sets, so even a root UID cannot perform privileged operations such as raw socket creation, binding to ports below 1024 (if governed by capability), or mounting filesystems. This is the correct least-privilege baseline; if a workload genuinely needs a specific capability, it can be added back selectively via `capabilities.add`. It directly reduces the kernel attack surface by denying access to privileged kernel operations.

  • ✗

    privileged: false

    Why it's wrong here

    `privileged: false` merely prevents the container from being granted all capabilities and accessing host devices; it does not strip the default capability set that every non-privileged container receives (e.g., CAP_CHOWN, CAP_DAC_OVERRIDE, CAP_FOWNER, CAP_KILL, CAP_SETUID, CAP_SETGID, CAP_NET_BIND_SERVICE, CAP_NET_RAW, CAP_SYS_CHROOT). Since `privileged: false` is the default value, setting it explicitly does not make the container more secure than the default configuration. To meaningfully reduce the attack surface, you must combine non-privileged mode with dropping capabilities and setting `allowPrivilegeEscalation: false`.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.