Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

You are writing a Rego policy for OPA/Gatekeeper to deny pods that do not have runAsNonRoot set to true. Which Rego statement should the ConstraintTemplate contain?

⚠ Common exam trap

The CKS exam often tests the distinction between pod-level and container-level security contexts, and the trap here is that candidates may incorrectly use `deny[msg]` with a positive condition or check container-level fields instead of the pod-level `runAsNonRoot` field.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

violation[msg] { not input.request.object.spec.securityContext.runAsNonRoot == true }

The Rego rule `violation[msg]` is the standard pattern for Gatekeeper ConstraintTemplates to deny a resource. The condition `not input.request.object.spec.securityContext.runAsNonRoot == true` triggers a violation when the field is missing or set to false, ensuring pods do not have `runAsNonRoot` set to true. This directly enforces the requirement to deny pods without the security context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    violation[msg] { not input.request.object.spec.securityContext.runAsNonRoot == true }

    Why this is correct

    The violation rule is the only construct Gatekeeper's constraint framework evaluates for admission decisions. By using 'not input...runAsNonRoot == true', the expression is satisfied whenever the field is absent, undefined, or set to false — including pods that omit pod-level securityContext entirely — so every non-compliant pod is denied while explicitly compliant pods pass. This matches the intended policy exactly.

  • ✗

    deny[msg] { input.request.object.spec.securityContext.runAsNonRoot == true }

    Why it's wrong here

    This rule inverts the required control, generating a deny message only when runAsNonRoot is true, which means compliant, non-root pods are blocked while insecure pods sail through. Additionally, Gatekeeper constraint templates do not consume arbitrary 'deny' rules; they require a 'violation' rule containing the 'msg' variable for the admission decision, so even the rule name is mechanically ineffective.

  • ✗

    allow[msg] { input.request.object.spec.securityContext.runAsNonRoot == false }

    Why it's wrong here

    'allow' rules are not evaluated by Gatekeeper's admission webhook; the policy engine looks for violations, not allowed results, so a pod that triggers this rule produces no denial and insecure workloads are accepted. Even if allow semantics existed, this expression matches pods where runAsNonRoot is explicitly false, which is precisely the insecure condition the policy was written to forbid.

  • ✗

    deny[msg] { input.request.object.spec.containers[_].securityContext.runAsNonRoot == true }

    Why it's wrong here

    This only inspects container-level securityContext entries, so a pod relying on pod-level runAsNonRoot: true — the standard placement for the setting — is never evaluated and, worse, the rule denies only when a container-level value is true, rejecting compliant containers while accepting containers that omit or explicitly set false. Container-level securityContext can also override pod-level settings, but the correct policy must evaluate the effective pod-level value, not any one container's flag.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.