Courseiva
System Hardening →easyMultiple Choice

CKS System Hardening Practice Question

Which Pod Security Standard level allows the use of hostNetwork, hostPID, and hostIPC?

⚠ Common exam trap

CNCF often tests the misconception that Baseline allows host-level namespace sharing, when in fact Baseline only permits a limited set of non-host-level privileges, while hostNetwork, hostPID, and hostIPC are exclusive to the Privileged level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Privileged

The Privileged Pod Security Standard (PSS) level is the most permissive, allowing unrestricted access to host-level resources, including hostNetwork, hostPID, and hostIPC. These settings grant the pod direct access to the host's network namespace, process table, and inter-process communication mechanisms, which are explicitly prohibited in the Baseline and Restricted levels. The Privileged level is designed for system-level workloads that require such elevated permissions, such as CNI plugins or monitoring agents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    None of the above

    Why it's wrong here

    The Pod Security Standards (PSS) enumerate three distinct policies: Privileged, Baseline, and Restricted. Among these, the Privileged level explicitly allows unrestricted access to host namespaces, so hostNetwork usage is permitted. Since one of the listed levels is correct, the claim that none apply is factually inaccurate and cannot be the right answer.

  • ✗

    Baseline

    Why it's wrong here

    Baseline is designed to prevent known privilege escalations while still enabling standard workloads, but it specifically forbids sharing host namespaces with the node. Under Baseline, fields such as hostNetwork, hostPID, and hostIPC are prohibited and will cause a pod to be rejected during admission. Therefore, enabling hostNetwork would violate Baseline policy, making it an incorrect choice.

  • ✓

    Privileged

    Why this is correct

    The Privileged level is intentionally the most permissive Pod Security Standard, imposing no restrictions on the pod's security context or namespace usage. It explicitly permits access to host namespaces, so setting hostNetwork to true is allowed without any policy interference. This is why Privileged is the only standard among the three that satisfies the requirement in the question.

  • ✗

    Restricted

    Why it's wrong here

    Restricted is the most hardened Pod Security Standard, layering additional constraints on top of Baseline for defense-in-depth. It categorically forbids host namespaces, requiring that hostNetwork, hostPID, and hostIPC be absent or false in the pod spec. A workload that sets hostNetwork would therefore be denied by admission control under a Restricted policy.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which Pod Security Standard level allows the most relaxed security controls?

easy
  • A.restricted
  • B.default
  • C.baseline
  • ✓ D.privileged

Why D: The privileged Pod Security Standard (PSS) level imposes no restrictions on pod behavior, allowing unrestricted access to host resources, capabilities, and security contexts. This makes it the most relaxed level, as it does not enforce any of the constraints found in baseline or restricted profiles.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.