CKS System Hardening Practice Question
What is the default seccomp profile applied when a pod's security context has 'seccompProfile.type: RuntimeDefault'?
⚠ Common exam trap
CNCF often tests the misconception that `RuntimeDefault` refers to Docker's legacy default profile (which blocks ~300 syscalls), when in fact it refers to the container runtime's own default (which blocks ~40 syscalls), and candidates may confuse it with `Unconfined` or a custom localhost path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The container runtime's default seccomp profile, which blocks around 40 syscalls
When `seccompProfile.type: RuntimeDefault` is set in a pod's security context, the container runtime (e.g., containerd or CRI-O) applies its own default seccomp profile. This runtime default profile is a curated allowlist that blocks approximately 40 syscalls known to be dangerous or unnecessary for containers, providing a balance between security and compatibility. It is not the Docker default (which blocks ~300 syscalls) but a more permissive profile tailored to the runtime's container model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The profile defined in /var/lib/kubelet/seccomp/default.json
Why it's wrong here
RuntimeDefault does not reference any host filesystem path. The path /var/lib/kubelet/seccomp/default.json would only be meaningful if the seccompProfile.type were set to Localhost, which loads a custom profile from a node-local file. When this type is RuntimeDefault, the kubelet simply tells the container runtime to apply its own built-in policy, so no file lookup occurs and this option is incorrect.
- ✗
Unconfined (no seccomp)
Why it's wrong here
Unconfined means no seccomp filter is attached to the container, so every syscall is permitted and the kernel performs no filtering beyond its default access controls. RuntimeDefault is the opposite: it instructs the runtime to install a deliberately restrictive profile. Because the question asks specifically about the default profile applied for RuntimeDefault, 'unconfined' is not the correct answer.
- ✗
The Docker default profile, which blocks around 300 syscalls
Why it's wrong here
Docker's classic default seccomp profile is renowned for blocking over 300 syscalls, but Kubernetes does not directly rely on that profile. In a typical Kubernetes cluster, the container runtime is containerd or CRI-O, each with its own default seccomp profile derived from the Docker reference but often more permissive. RuntimeDefault delegates to the runtime's own default (blocking fewer syscalls, about 40), so neither the source nor the syscall count in this option matches.
- ✓
The container runtime's default seccomp profile, which blocks around 40 syscalls
Why this is correct
With seccompProfile.type set to RuntimeDefault, the kubelet asks the container runtime (e.g., containerd) to apply its built-in default seccomp filter. This runtime-owned profile blocks roughly 40 syscalls that are considered dangerous or unnecessary in a container, such as mounting filesystems or kernel module loading, while allowing normal application syscalls. It is the correct answer because it accurately names both the source (the runtime) and the approximate number of blocked syscalls.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.