Courseiva
System Hardening →easyMultiple Choice

CKS System Hardening Practice Question

Which Pod Security Standard level allows the most relaxed security controls?

⚠ Common exam trap

Many exam-takers confuse 'default' with a valid PSS level, or assume 'baseline' is the most relaxed because it sounds less restrictive than 'restricted', but privileged explicitly allows all controls without limitation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

privileged

The privileged Pod Security Standard (PSS) level imposes no restrictions on pod behavior, allowing unrestricted access to host resources, capabilities, and security contexts. This makes it the most relaxed level, as it does not enforce any of the constraints found in baseline or restricted profiles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    restricted

    Why it's wrong here

    Restricted is the most stringent Pod Security Standard level, deliberately positioned at the opposite end of the spectrum from relaxed. It requires workloads to run with seccomp set to RuntimeDefault, forbids privileged containers, blocks host namespaces (hostNetwork, hostPID, hostIPC), disallows privilege escalation, and restricts Linux capabilities to a short allowlist. Thus, choosing restricted would impose the strictest possible controls, not a relaxed posture.

  • ✗

    default

    Why it's wrong here

    Default is not a Pod Security Standard level at all; the three standard levels are privileged, baseline, and restricted. The term "default" commonly refers to a namespace's admission control enforcement action (like warn, audit, or enforce) or the default configuration of Pod Security Admission, which applies the privileged level when no labels are set. Therefore, selecting "default" as a security level is conceptually invalid and cannot represent the most relaxed standard.

  • ✗

    baseline

    Why it's wrong here

    Baseline occupies a middle ground between privileged and restricted, targeting known privilege-escalation risks while allowing typical workloads. It blocks privileged containers, hostNetwork, hostPID, hostIPC, and certain Linux capabilities (e.g., CAP_SYS_ADMIN), but still permits many non-hardened behaviors like arbitrary seccomp profiles or unconstrained file systems. Because it enforces a meaningful set of restrictions, baseline is nowhere near the most relaxed Pod Security Standard level.

  • ✓

    privileged

    Why this is correct

    Privileged is the most relaxed Pod Security Standard level, imposing virtually no security restrictions on pods. It allows privileged containers, all Linux capabilities, host namespaces (network, PID, IPC), arbitrary seccomp or AppArmor overrides, and ephemeral containers, making it suitable only for system-level or trusted workloads. This design intentionally matches the behavior of running with no Pod Security admission restrictions, hence it is the correct answer.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.