CKS Minimize Microservice Vulnerabilities Practice Question
Which of the following is a characteristic of Kata Containers compared to gVisor?
⚠ Common exam trap
It's easy for candidates to confuse gVisor's user-space kernel approach (system call interception) with Kata Containers' hardware virtualization, leading them to select option D, which accurately describes gVisor but not Kata Containers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kata Containers use lightweight VMs to isolate containers
Kata Containers use lightweight virtual machines (VMs) to provide strong hardware-enforced isolation for containers. Each container runs inside its own minimal VM with a separate kernel, offering security comparable to a VM while maintaining container-like performance and orchestration. This is the defining characteristic that distinguishes Kata Containers from gVisor.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Kata Containers require no additional configuration in Kubernetes
Why it's wrong here
In Kubernetes, Kata Containers cannot be used without explicit additional configuration. You must install the Kata runtime on each node, define a RuntimeClass (e.g., system-runtime-class=class.kata-containers.io/kata-qemu), and then assign that RuntimeClass to Pods via the Pod spec. The kubelet also needs to be configured to recognize the kata runtime handler. Thus the claim that no extra configuration is required is incorrect.
- ✗
Kata Containers have lower overhead than gVisor
Why it's wrong here
Kata Containers typically have higher overhead than gVisor, not lower. Kata boots a lightweight virtual machine with its own relatively complete kernel for each container, incurring startup latency, extra memory for the guest kernel, and virtualization costs. gVisor, by contrast, runs a user-space kernel (Sentry) that intercepts system calls without needing a hardware VM, so its per-container overhead is generally lower. The premise that Kata has lower overhead is wrong; it uses a heavier isolation mechanism.
- ✓
Kata Containers use lightweight VMs to isolate containers
Why this is correct
Kata Containers use lightweight virtual machines to isolate containers, providing a hardware-level security boundary. Each container or pod runs inside its own VM, using a guest kernel and hardware virtualization (e.g., via QEMU, Cloud Hypervisor, or Firecracker), while still offering container interfaces like OCI. This design delivers stronger isolation than standard runc or even gVisor, because a separate kernel and hardware virtualization protect against many host-validating side channels. This is precisely the defining characteristic of Kata Containers.
- ✗
Kata Containers provide a user-space kernel that intercepts system calls
Why it's wrong here
The behavior of a user-space kernel that intercepts system calls is the hallmark of gVisor, not Kata Containers. Kata uses hardware virtualization to run a standard Linux kernel inside a VM; it does not rely on a user-space syscall-interception layer. gVisor's Sentry handles syscalls in user space and spoofs kernel boundaries, whereas Kata's VM provides a true kernel boundary via hardware-assisted virtualization. Therefore, this option incorrectly describes a gVisor feature as a Kata characteristic.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.