CKS System Hardening Practice Question
You are creating a custom seccomp profile for a container that runs a binary requiring the 'write' syscall only. You place the profile JSON file at '/var/lib/kubelet/seccomp/profiles/write-only.json'. In the pod spec, which seccomp configuration correctly uses this profile?
⚠ Common exam trap
CNCF often tests the distinction between relative and absolute paths for 'localhostProfile', and the trap here is that candidates mistakenly use an absolute path (option B) or confuse the field name 'localhostProfile' with 'profile' (option D), while also testing that 'type: RuntimeDefault' cannot be combined with a custom profile path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
securityContext: seccompProfile: type: Localhost localhostProfile: profiles/write-only.json
When using a custom seccomp profile with type 'Localhost', the 'localhostProfile' field must specify a path relative to the kubelet's seccomp root directory (default: /var/lib/kubelet/seccomp). The path 'profiles/write-only.json' is relative and resolves to /var/lib/kubelet/seccomp/profiles/write-only.json, matching the file location. The 'type' field must be 'Localhost' to reference a local profile file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
securityContext: seccompProfile: type: RuntimeDefault localhostProfile: profiles/write-only.json
Why it's wrong here
Setting `type: RuntimeDefault` instructs the container runtime to apply its built-in default seccomp profile, which already provides a sensible set of allowed syscalls. The `localhostProfile` field is only meaningful when `type: Localhost` is specified; including it with `RuntimeDefault` is invalid and the API server may reject it or ignore it, but in no case will the custom write-only profile be loaded. You cannot mix a vendor-defined default with a local file path.
- ✗
securityContext: seccompProfile: type: Localhost localhostProfile: /var/lib/kubelet/seccomp/profiles/write-only.json
Why it's wrong here
The `localhostProfile` field must be a relative path, resolved by the kubelet against its seccomp profile root, typically `/var/lib/kubelet/seccomp`. Passing an absolute path such as `/var/lib/kubelet/seccomp/profiles/write-only.json` causes the kubelet to concatenate that entire string to the root, resulting in a path like `/var/lib/kubelet/seccomp/var/lib/kubelet/seccomp/profiles/write-only.json`, which does not exist. Therefore, the file cannot be found and the pod fails to start. Use `profiles/write-only.json` instead.
- ✓
securityContext: seccompProfile: type: Localhost localhostProfile: profiles/write-only.json
Why this is correct
This snippet correctly defines a custom seccomp profile by setting `type: Localhost` and providing `localhostProfile: profiles/write-only.json`, a relative path. The kubelet resolves this path relative to its seccomp profile directory, typically `/var/lib/kubelet/seccomp`, so the actual file must exist at `/var/lib/kubelet/seccomp/profiles/write-only.json`. This is the only one of the four options that would successfully load the write-only profile.
- ✗
securityContext: seccompProfile: type: Localhost profile: write-only.json
Why it's wrong here
The seccompProfile API has no field named `profile`; the correct key is `localhostProfile`, which is required when `type` is `Localhost`. Submitting `profile` as a field causes the Kubernetes API server to reject the manifest because the field is not recognized in the `SeccompProfile` schema. Additionally, the value `write-only.json` lacks the `profiles/` directory prefix, so even a corrected field name would not resolve to the intended file in the kubelet's seccomp root.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.