Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

Which of the following is the correct way to drop all capabilities in a container's security context?

⚠ Common exam trap

The CKS exam often tests the distinction between `drop` and `add` fields, and candidates may mistakenly think that setting `add: []` or an empty `capabilities` list achieves the same effect as dropping all capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

securityContext: capabilities: drop: ['ALL']

In Kubernetes, the `securityContext.capabilities.drop` field is used to explicitly remove Linux capabilities from a container. Setting `drop: ['ALL']` removes all capabilities, ensuring the container runs with the least privilege. This is the standard and recommended way to harden container security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    securityContext: capabilities: drop: ['ALL']

    Why this is correct

    Setting securityContext.capabilities.drop to ['ALL'] is the correct Kubernetes syntax for revoking every Linux capability from the container's effective/permitted/bounding sets. This ensures the process starts with no capabilities, and you can selectively re-add specific capabilities using the add field. It is the recognized approach for least privilege and is required by restricted Pod Security Standards.

  • ✗

    securityContext: capabilities: remove: ['ALL']

    Why it's wrong here

    The capabilities field in a Kubernetes securityContext only supports add and drop subfields; there is no remove key. Specifying remove: ['ALL'] would either be rejected by the API server under strict schema validation or silently ignored as an unknown field on older versions. The intended operation is expressed solely by drop, so this option is invalid.

  • ✗

    securityContext: capabilities: []

    Why it's wrong here

    Declaring capabilities: [] supplies an empty object, which simply means no capability requests are being made; it neither adds nor removes anything. As a result, the container inherits the runtime's default capability set, such as CHOWN, DAC_OVERRIDE, FOWNER, and others, leaving the container more privileged than intended. Dropping all capabilities requires an explicit drop entry with the ALL value.

  • ✗

    securityContext: capabilities: add: []

    Why it's wrong here

    Using add: [] explicitly instructs Kubernetes to add an empty list of capabilities, so no capabilities are added beyond the defaults. However, the default capabilities are still granted unless a corresponding drop is specified, meaning the container's privilege surface remains unchanged. To drop current capabilities you must list them in the drop field; adding blank entries is a no-op.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.