CKS Minimize Microservice Vulnerabilities Practice Question
Which field in a Pod's securityContext prevents privilege escalation by the container?
⚠ Common exam trap
CNCF often tests this by having candidates confuse `allowPrivilegeEscalation` with `runAsNonRoot`, where the trap is that `runAsNonRoot` only sets the initial user but does not block subsequent privilege escalation via setuid binaries or capability-based syscalls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
allowPrivilegeEscalation
`allowPrivilegeEscalation` controls whether a process can gain more privileges than its parent process. In a Pod's securityContext, setting this field to `false` prevents the container from performing privilege escalation, such as via setuid binaries or system calls like `setuid(0)`. This directly mitigates a common attack vector where an attacker exploits a container process to gain root access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
capabilities.add: ["SYS_ADMIN"]
Why it's wrong here
Adding the SYS_ADMIN capability is a deliberate privilege expansion: it grants the process a highly privileged Linux capability that includes operations such as mounting filesystems, manipulating namespaces, and performing other administrative actions. Because capabilities.add extends the container's permitted privileges rather than restricting them, it cannot prevent privilege escalation. In fact, SYS_ADMIN may actually enable additional escalation pathways by giving the process more control over its environment.
- ✗
runAsNonRoot
Why it's wrong here
The runAsNonRoot field only enforces that the container's initial user ID is not 0 (root) when the container starts; it performs a static check before process execution. It does not control the process's ability to change its UID or gain additional privileges after startup, such as through setuid binaries or file capabilities. Thus, while it reduces the initial attack surface, it does not directly prevent privilege escalation, because the process can still escalate from the non-root user if vulnerabilities or misconfigurations exist.
- ✓
allowPrivilegeEscalation
Why this is correct
This field is the direct and intended control for privilege escalation. Setting allowPrivilegeEscalation: false applies the Linux no_new_privs attribute to all processes in the container, which prevents them from gaining more privileges than their parent process, including setuid/setgid executions and file capability acquisition. It is a runtime security feature that blocks the actual mechanism of privilege escalation, making it the correct answer. Without this setting, a container running as a non-root user may still escalate to root via a setuid binary.
- ✗
privileged
Why it's wrong here
Setting privileged: false only stops the container from being granted all capabilities and unrestricted access to host devices, which is a broad, coarse-grained restriction. It does not disable the kernel's ability to change process credentials; a non-privileged container can still execute setuid binaries or gain additional capabilities through other kernel-mediated mechanisms unless allowPrivilegeEscalation is explicitly set to false. Therefore, privileged: false is a necessary but not sufficient condition for preventing privilege escalation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.