CKS Minimize Microservice Vulnerabilities Practice Question
Which THREE of the following are features of container sandboxing solutions like gVisor or Kata Containers?
⚠ Common exam trap
The CKS exam often tests the misconception that sandboxing improves performance, when in reality the added isolation layer (user-space kernel or VM) introduces latency and resource overhead compared to native runc.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They are compatible with the OCI runtime specification
Both gVisor and Kata Containers implement the OCI (Open Container Initiative) runtime specification, which allows them to be used as drop-in replacements for runc. This compatibility ensures that container images and tools like containerd can interface with these sandboxed runtimes without modification, as they expose the same runtime lifecycle commands (create, start, delete).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
They are compatible with the OCI runtime specification
Why this is correct
Container sandboxes such as gVisor (runsc) and Kata Containers implement the OCI runtime specification, meaning they expose the same lifecycle commands (create, start, delete) and expect the same OCI image/bundle format. This allows containerd or CRI-O to treat them as drop-in replacements for runc, requiring no changes to the kubelet, container images, or orchestration workflows. OCI compatibility is therefore a core enabler for using these sandboxes in Kubernetes without breaking existing tooling.
- ✗
They improve container performance over native runc
Why it's wrong here
Sandboxing generally adds overhead and reduces performance compared to native runc, not improves it. gVisor incurs latency by intercepting and translating system calls through a user-space kernel, while Kata Containers pays the cost of booting a lightweight virtual machine and performing hardware-virtualized I/O. CPU-, syscall-, or network-heavy workloads can see noticeably lower throughput and higher latency, so sandboxes are chosen for stronger isolation rather than speed.
- ✓
They can be used with RuntimeClass to select the sandbox runtime per pod
Why this is correct
Kubernetes RuntimeClass is the built-in mechanism for choosing a sandbox runtime on a per-pod basis. An administrator defines a RuntimeClass object whose handler points to a specific sandbox runtime (for example, runsc or kata), and then a pod can declare `runtimeClassName` to request that isolation level. This enables mixed clusters where untrusted or sensitive workloads run inside sandboxes while other pods continue using runc, all under standard Kubernetes scheduling semantics.
- ✓
They provide an additional layer of isolation between containers and the host kernel
Why this is correct
Sandboxing solutions add a security boundary between the container and the host kernel. Kata Containers places each pod in a lightweight virtual machine with its own Linux guest kernel, whereas gVisor implements an application kernel in Go that mediates system calls before they ever reach the host. This extra layer prevents a compromised container from directly exploiting host kernel vulnerabilities, providing defense-in-depth beyond the traditional namespace, cgroup, and seccomp isolation used by runc.
- ✗
They use the host kernel directly for all system calls
Why it's wrong here
The defining behavior of native runc is executing containers with direct access to the host kernel for system calls; sandboxes explicitly avoid that. gVisor intercepts system calls and either emulates them or converts them into guarded host operations through a user-space kernel, while Kata routes system calls to an isolated guest kernel inside a VM. Thus a sandboxed container never makes unfiltered, direct syscalls to the host kernel, which is exactly what makes it more resistant to kernel-based container escape attacks than runc.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.