Courseiva
System Hardening →easyMultiple Choice

CKS System Hardening Practice Question

What is the default seccomp profile applied when a pod's security context has 'seccompProfile.type: RuntimeDefault'?

⚠ Common exam trap

CNCF often tests the misconception that `RuntimeDefault` refers to Docker's legacy default profile (which blocks ~300 syscalls), when in fact it refers to the container runtime's own default (which blocks ~40 syscalls), and candidates may confuse it with `Unconfined` or a custom localhost path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The container runtime's default seccomp profile, which blocks around 40 syscalls

When `seccompProfile.type: RuntimeDefault` is set in a pod's security context, the container runtime (e.g., containerd or CRI-O) applies its own default seccomp profile. This runtime default profile is a curated allowlist that blocks approximately 40 syscalls known to be dangerous or unnecessary for containers, providing a balance between security and compatibility. It is not the Docker default (which blocks ~300 syscalls) but a more permissive profile tailored to the runtime's container model.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The profile defined in /var/lib/kubelet/seccomp/default.json

    Why it's wrong here

    RuntimeDefault does not reference any host filesystem path. The path /var/lib/kubelet/seccomp/default.json would only be meaningful if the seccompProfile.type were set to Localhost, which loads a custom profile from a node-local file. When this type is RuntimeDefault, the kubelet simply tells the container runtime to apply its own built-in policy, so no file lookup occurs and this option is incorrect.

  • ✗

    Unconfined (no seccomp)

    Why it's wrong here

    Unconfined means no seccomp filter is attached to the container, so every syscall is permitted and the kernel performs no filtering beyond its default access controls. RuntimeDefault is the opposite: it instructs the runtime to install a deliberately restrictive profile. Because the question asks specifically about the default profile applied for RuntimeDefault, 'unconfined' is not the correct answer.

  • ✗

    The Docker default profile, which blocks around 300 syscalls

    Why it's wrong here

    Docker's classic default seccomp profile is renowned for blocking over 300 syscalls, but Kubernetes does not directly rely on that profile. In a typical Kubernetes cluster, the container runtime is containerd or CRI-O, each with its own default seccomp profile derived from the Docker reference but often more permissive. RuntimeDefault delegates to the runtime's own default (blocking fewer syscalls, about 40), so neither the source nor the syscall count in this option matches.

  • ✓

    The container runtime's default seccomp profile, which blocks around 40 syscalls

    Why this is correct

    With seccompProfile.type set to RuntimeDefault, the kubelet asks the container runtime (e.g., containerd) to apply its built-in default seccomp filter. This runtime-owned profile blocks roughly 40 syscalls that are considered dangerous or unnecessary in a container, such as mounting filesystems or kernel module loading, while allowing normal application syscalls. It is the correct answer because it accurately names both the source (the runtime) and the approximate number of blocked syscalls.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.