CKS Minimize Microservice Vulnerabilities Practice Question
Which of the following is a valid approach to enforce that containers cannot escalate privileges?
⚠ Common exam trap
CNCF often tests the misconception that dropping all capabilities or setting `privileged: false` is sufficient to prevent privilege escalation, but the key is that `allowPrivilegeEscalation: false` is required to block setuid-based escalation, which is a separate kernel mechanism from capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set securityContext.allowPrivilegeEscalation: false
Setting `securityContext.allowPrivilegeEscalation: false` directly prevents a container from gaining more privileges than its parent process, such as through setuid binaries or `NO_NEW_PRIVS` flag. This is a key control to block privilege escalation attacks even if the container runs with some capabilities. It is enforced at the kernel level via the `no_new_privs` attribute, which disables privilege-gaining operations like `setuid` and `setgid`.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set securityContext.readOnlyRootFilesystem: true
Why it's wrong here
Setting readOnlyRootFilesystem: true mounts the root filesystem as read-only, which prevents write operations to system files but does not address privilege escalation. Privilege escalation techniques such as executing a setuid binary or gaining additional capabilities do not rely on filesystem write access. Therefore, this setting alone leaves allowPrivilegeEscalation effectively unrestricted, and it does not satisfy the requirement to prevent processes from elevating privileges.
- ✗
Set securityContext.privileged: false
Why it's wrong here
privileged: false is already the default behavior for any container and simply ensures the container is not granted all capabilities and host access like a privileged container. However, it does not disable mechanisms like setuid executables, file capabilities, or other kernel interfaces that can increase a process's effective privileges beyond its parent. Thus, explicitly setting privileged: false provides no additional protection against privilege escalation and is unrelated to the allowPrivilegeEscalation control.
- ✗
Set securityContext.capabilities.drop: ["ALL"]
Why it's wrong here
Dropping all capabilities with capabilities.drop: ['ALL'] removes the container's Linux capabilities such as CAP_NET_BIND_SERVICE or CAP_SYS_ADMIN, which reduces the attack surface. Nevertheless, dropping capabilities does not prevent a process from escalating via setuid bits or from gaining capabilities afterwards if the binary or interpreter is configured with file capabilities. Since these escalation paths are independent of the capability bounding set, this setting cannot be considered a valid method to enforce that processes cannot gain more privileges.
- ✓
Set securityContext.allowPrivilegeEscalation: false
Why this is correct
Setting allowPrivilegeEscalation: false instructs the runtime to set the no_new_privs attribute on the container process, which prevents any child process from gaining more privileges than the parent, including via setuid binaries or file capabilities. This is the direct and supported method to enforce that containers cannot escalate privileges, and it works at the kernel level. It is also required by many security policies and is a key control in pod security standards.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.