Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

Which field must be set in a Pod's security context to prevent the container from running as the root user?

⚠ Common exam trap

The CKS exam often tests the distinction between `runAsUser` (which sets the user but does not enforce non-root) and `runAsNonRoot` (which enforces non-root), leading candidates to mistakenly choose `runAsUser: 1000` thinking it prevents root execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

runAsNonRoot: true

The `runAsNonRoot: true` field in a Pod's security context enforces that the container's entrypoint cannot run as UID 0 (root). If the container image attempts to run as root, the container runtime (e.g., containerd) will reject the container from starting, ensuring compliance with the principle of least privilege and mitigating root-based container escapes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    runAsUser: 1000

    Why it's wrong here

    Setting runAsUser to 1000 specifies a non-root UID, but the question asks which field prevents root execution; runAsNonRoot is the field that enforces this. It is tempting because a non-zero UID does run as non-root, yet without runAsNonRoot Kubernetes cannot verify the image's declared user.

  • ✗

    readOnlyRootFilesystem: true

    Why it's wrong here

    readOnlyRootFilesystem mounts the container's root filesystem read-only, which limits tampering but does not change the user the process runs as. It is tempting as a container-hardening control, yet root execution persists; runAsNonRoot is the field that blocks it.

  • ✗

    allowPrivilegeEscalation: false

    Why it's wrong here

    allowPrivilegeEscalation controls whether a process can gain more privileges than its parent, not which UID the container runs as. It is tempting because it hardens containers against setuid escalation, but it leaves the container free to start as root, so runAsNonRoot is required instead.

  • ✓

    runAsNonRoot: true

    Why this is correct

    Setting runAsNonRoot: true makes the kubelet reject any container whose image or configuration would start as UID 0, satisfying the stem's prevention requirement. It enforces non-root execution at admission and runtime rather than merely documenting intent.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.