CKS System Hardening Practice Question
Which of the following is the correct way to drop all Linux capabilities for a container?
⚠ Common exam trap
CNCF often tests the distinction between singular `capability` and plural `capabilities` in the YAML field name, as well as the difference between `drop: ["ALL"]` and `add: ["ALL"]`, to catch candidates who misremember the exact syntax or confuse dropping with adding capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
capabilities: drop: ["ALL"]
In a Kubernetes Pod security context, the `capabilities` field is a list of capabilities to add or drop. Dropping `ALL` removes all Linux capabilities from the container, which is the most restrictive and secure approach. The correct YAML syntax uses `capabilities:` (plural) with a `drop:` list containing `"ALL"`.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
capability: drop: ["ALL"]
Why it's wrong here
The `capability` key is misspelled; the correct Kubernetes securityContext field is `capabilities` (plural). Because of this typo, the field is not recognized by the kubelet, so the intended drop is silently ignored and the container runs with its default capability set. This does not achieve dropping all Linux capabilities and may also cause a schema validation error in stricter API servers.
- ✗
capabilities: drop: ["NET_RAW", "CHOWN"]
Why it's wrong here
This configuration correctly uses the `capabilities` field and the `drop` list, but it only removes the two named capabilities, `NET_RAW` and `CHOWN`. Other capabilities, such as `DAC_OVERRIDE` or `SETUID`, remain active, so the container still has a broad set of permissions. To drop all capabilities, you must use the special token `ALL` rather than enumerating a partial list.
- ✓
capabilities: drop: ["ALL"]
Why this is correct
This is the correct and idiomatic way to drop all Linux capabilities in a Kubernetes container. The plural `capabilities` field is recognized by the securityContext schema, and the special case-insensitive token `ALL` (conventionally uppercase) instructs the runtime to remove every capability from the container's effective, permitted, and inherited sets. The result is a process with no capabilities, ideal for least-privilege workloads.
- ✗
capabilities: add: ["ALL"]
Why it's wrong here
This uses `add` instead of `drop`, which has the opposite effect: it grants the container every Linux capability, including those that many runtimes drop by default. Adding `ALL` explicitly elevates the process's privileges to the maximum possible, expanding its attack surface and violating the principle of least privilege. It does nothing to drop any capabilities, so it is fundamentally incorrect for this requirement.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Container Image Security
Key term
Pod Security Admission
Pod Security Admission is a Kubernetes feature that enforces security standards on pods at creation time to prevent running containers with dangerous privileges.
Key term
Pod Security Standards
Pod Security Standards are a set of predefined Kubernetes policies that control the security context of pods to prevent privilege escalation and enforce least privilege.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.