CKS Minimize Microservice Vulnerabilities Practice Question
You are writing a Rego policy for OPA/Gatekeeper to deny pods that do not have runAsNonRoot set to true. Which Rego statement should the ConstraintTemplate contain?
⚠ Common exam trap
The CKS exam often tests the distinction between pod-level and container-level security contexts, and the trap here is that candidates may incorrectly use `deny[msg]` with a positive condition or check container-level fields instead of the pod-level `runAsNonRoot` field.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
violation[msg] { not input.request.object.spec.securityContext.runAsNonRoot == true }
The Rego rule `violation[msg]` is the standard pattern for Gatekeeper ConstraintTemplates to deny a resource. The condition `not input.request.object.spec.securityContext.runAsNonRoot == true` triggers a violation when the field is missing or set to false, ensuring pods do not have `runAsNonRoot` set to true. This directly enforces the requirement to deny pods without the security context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
violation[msg] { not input.request.object.spec.securityContext.runAsNonRoot == true }
Why this is correct
The violation rule is the only construct Gatekeeper's constraint framework evaluates for admission decisions. By using 'not input...runAsNonRoot == true', the expression is satisfied whenever the field is absent, undefined, or set to false — including pods that omit pod-level securityContext entirely — so every non-compliant pod is denied while explicitly compliant pods pass. This matches the intended policy exactly.
- ✗
deny[msg] { input.request.object.spec.securityContext.runAsNonRoot == true }
Why it's wrong here
This rule inverts the required control, generating a deny message only when runAsNonRoot is true, which means compliant, non-root pods are blocked while insecure pods sail through. Additionally, Gatekeeper constraint templates do not consume arbitrary 'deny' rules; they require a 'violation' rule containing the 'msg' variable for the admission decision, so even the rule name is mechanically ineffective.
- ✗
allow[msg] { input.request.object.spec.securityContext.runAsNonRoot == false }
Why it's wrong here
'allow' rules are not evaluated by Gatekeeper's admission webhook; the policy engine looks for violations, not allowed results, so a pod that triggers this rule produces no denial and insecure workloads are accepted. Even if allow semantics existed, this expression matches pods where runAsNonRoot is explicitly false, which is precisely the insecure condition the policy was written to forbid.
- ✗
deny[msg] { input.request.object.spec.containers[_].securityContext.runAsNonRoot == true }
Why it's wrong here
This only inspects container-level securityContext entries, so a pod relying on pod-level runAsNonRoot: true — the standard placement for the setting — is never evaluated and, worse, the rule denies only when a container-level value is true, rejecting compliant containers while accepting containers that omit or explicitly set false. Container-level securityContext can also override pod-level settings, but the correct policy must evaluate the effective pod-level value, not any one container's flag.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.