Courseiva
System Hardening →mediumMultiple Select

CKS System Hardening Practice Question

Which TWO of the following are valid Pod Security Standards levels?

⚠ Common exam trap

The CKS exam often tests the exact naming of the three Pod Security Standards levels, and candidates mistakenly invent plausible-sounding names like 'secure', 'default', or 'strict' instead of the official terms 'privileged', 'baseline', and 'restricted'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

privileged

The Pod Security Standards (PSS) define three levels: privileged, baseline, and restricted. 'Privileged' is the most permissive level, allowing all known privilege escalations and is intended for system-level workloads that require unrestricted access to host resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    secure

    Why it's wrong here

    The term 'secure' is not a defined level in the Pod Security Standards. The Kubernetes documentation lists exactly three levels: privileged, baseline, and restricted. While a policy that adopts 'restricted' could be described as 'secure,' that is not its official name. Therefore, 'secure' is not a valid answer.

  • ✗

    default

    Why it's wrong here

    'Default' is also not a Pod Security Standard level. The three standard levels are privileged, baseline, and restricted, and there is no 'default' policy level. Although a namespace can be configured with no explicit enforcement label (which results in permissive behavior), that does not correspond to a named standard. Thus, 'default' is not a valid level.

  • ✓

    privileged

    Why this is correct

    Privileged is the first and most permissive Pod Security Standard level. It intentionally imposes no restrictions on the pod security context, allowing privileged containers, host namespaces, and arbitrary capabilities. This level is commonly used for system-level pods such as cluster add-ons that require direct host access. It is a valid level according to the Pod Security Standards.

  • ✓

    baseline

    Why this is correct

    Baseline is the middle level of the Pod Security Standards, providing a set of minimum restrictions to prevent known privilege escalations while supporting typical applications. It disallows privileged containers, hostPath volumes, host networking, and certain unsafe capabilities, among other controls. Baseline is a valid level, distinct from both privileged and restricted.

  • ✗

    strict

    Why it's wrong here

    'Strict' is not a valid level name in the Pod Security Standards. The most restrictive level is actually called 'restricted,' which imposes additional constraints like read-only root filesystems and dropping all capabilities. There is no official 'strict' policy; using this term indicates confusion with restricted. Therefore, 'strict' is not a correct choice.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are valid Pod Security Standard levels? (Select 2)

medium
  • A.medium
  • B.high
  • C.default
  • ✓ D.privileged
  • ✓ E.restricted

Why D: The Pod Security Standards (PSS) define three levels: privileged, baseline, and restricted. The privileged level is the most permissive, allowing known privilege escalations and is intended for system-level workloads that require unrestricted access to host resources. It is explicitly listed in the Kubernetes documentation as one of the three valid PSS levels.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.