CKS Minimize Microservice Vulnerabilities Practice Question
Which field must be set in a Pod's security context to prevent the container from running as the root user?
⚠ Common exam trap
The CKS exam often tests the distinction between `runAsUser` (which sets the user but does not enforce non-root) and `runAsNonRoot` (which enforces non-root), leading candidates to mistakenly choose `runAsUser: 1000` thinking it prevents root execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
runAsNonRoot: true
The `runAsNonRoot: true` field in a Pod's security context enforces that the container's entrypoint cannot run as UID 0 (root). If the container image attempts to run as root, the container runtime (e.g., containerd) will reject the container from starting, ensuring compliance with the principle of least privilege and mitigating root-based container escapes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
runAsUser: 1000
Why it's wrong here
Setting runAsUser to 1000 specifies a non-root UID, but the question asks which field prevents root execution; runAsNonRoot is the field that enforces this. It is tempting because a non-zero UID does run as non-root, yet without runAsNonRoot Kubernetes cannot verify the image's declared user.
- ✗
readOnlyRootFilesystem: true
Why it's wrong here
readOnlyRootFilesystem mounts the container's root filesystem read-only, which limits tampering but does not change the user the process runs as. It is tempting as a container-hardening control, yet root execution persists; runAsNonRoot is the field that blocks it.
- ✗
allowPrivilegeEscalation: false
Why it's wrong here
allowPrivilegeEscalation controls whether a process can gain more privileges than its parent, not which UID the container runs as. It is tempting because it hardens containers against setuid escalation, but it leaves the container free to start as root, so runAsNonRoot is required instead.
- ✓
runAsNonRoot: true
Why this is correct
Setting runAsNonRoot: true makes the kubelet reject any container whose image or configuration would start as UID 0, satisfying the stem's prevention requirement. It enforces non-root execution at admission and runtime rather than merely documenting intent.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.