CKS System Hardening Practice Question
Which TWO of the following are valid Pod Security Standards levels?
⚠ Common exam trap
The CKS exam often tests the exact naming of the three Pod Security Standards levels, and candidates mistakenly invent plausible-sounding names like 'secure', 'default', or 'strict' instead of the official terms 'privileged', 'baseline', and 'restricted'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
privileged
The Pod Security Standards (PSS) define three levels: privileged, baseline, and restricted. 'Privileged' is the most permissive level, allowing all known privilege escalations and is intended for system-level workloads that require unrestricted access to host resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
secure
Why it's wrong here
The term 'secure' is not a defined level in the Pod Security Standards. The Kubernetes documentation lists exactly three levels: privileged, baseline, and restricted. While a policy that adopts 'restricted' could be described as 'secure,' that is not its official name. Therefore, 'secure' is not a valid answer.
- ✗
default
Why it's wrong here
'Default' is also not a Pod Security Standard level. The three standard levels are privileged, baseline, and restricted, and there is no 'default' policy level. Although a namespace can be configured with no explicit enforcement label (which results in permissive behavior), that does not correspond to a named standard. Thus, 'default' is not a valid level.
- ✓
privileged
Why this is correct
Privileged is the first and most permissive Pod Security Standard level. It intentionally imposes no restrictions on the pod security context, allowing privileged containers, host namespaces, and arbitrary capabilities. This level is commonly used for system-level pods such as cluster add-ons that require direct host access. It is a valid level according to the Pod Security Standards.
- ✓
baseline
Why this is correct
Baseline is the middle level of the Pod Security Standards, providing a set of minimum restrictions to prevent known privilege escalations while supporting typical applications. It disallows privileged containers, hostPath volumes, host networking, and certain unsafe capabilities, among other controls. Baseline is a valid level, distinct from both privileged and restricted.
- ✗
strict
Why it's wrong here
'Strict' is not a valid level name in the Pod Security Standards. The most restrictive level is actually called 'restricted,' which imposes additional constraints like read-only root filesystems and dropping all capabilities. There is no official 'strict' policy; using this term indicates confusion with restricted. Therefore, 'strict' is not a correct choice.
Go deeper
Related to this question
Learn chapter
System Hardening: CIS Benchmarks and Auditing
Key term
Pod Security Standards
Pod Security Standards are a set of predefined Kubernetes policies that control the security context of pods to prevent privilege escalation and enforce least privilege.
Key term
Pod Security Admission
Pod Security Admission is a Kubernetes feature that enforces security standards on pods at creation time to prevent running containers with dangerous privileges.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are valid Pod Security Standard levels? (Select 2)
medium- A.medium
- B.high
- C.default
- ✓ D.privileged
- ✓ E.restricted
Why D: The Pod Security Standards (PSS) define three levels: privileged, baseline, and restricted. The privileged level is the most permissive, allowing known privilege escalations and is intended for system-level workloads that require unrestricted access to host resources. It is explicitly listed in the Kubernetes documentation as one of the three valid PSS levels.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.