CKS Minimize Microservice Vulnerabilities Practice Question
You need to ensure that all pods in a cluster run with read-only root filesystems. Which Pod Security Standard (PSS) control field should be set to true?
⚠ Common exam trap
The CKS exam often tests the distinction between pod-level and container-level security context fields, and candidates mistakenly look for a field under `spec` (like `spec.readOnlyRootFilesystem`) instead of the correct nested path `securityContext.readOnlyRootFilesystem` at the container level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
securityContext.readOnlyRootFilesystem
The Pod Security Standard (PSS) control field `securityContext.readOnlyRootFilesystem` must be set to `true` at the pod or container security context level to enforce a read-only root filesystem. This setting prevents containers from writing to their root filesystem, reducing the attack surface by limiting the ability to drop malicious binaries or modify system files. It is a key control under the 'Restricted' PSS profile for minimizing microservice vulnerabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
spec.readOnlyRootFilesystem
Why it's wrong here
spec.readOnlyRootFilesystem is invalid because readOnlyRootFilesystem is not a top-level pod spec field. The Kubernetes API schema only accepts this setting inside a container's securityContext (spec.containers[].securityContext.readOnlyRootFilesystem), so placing it at the pod spec level would either be rejected by the API server or silently ignored, and it cannot enforce a read-only root filesystem. Even the pod-level securityContext does not expose this option, so it must be applied per container.
- ✗
securityContext.privileged: false
Why it's wrong here
securityContext.privileged: false only prevents the container from running in privileged mode, which is already the default in most clusters; it does nothing to restrict writes to the container's root filesystem. A non-privileged container still gets a writable rootfs, so an application can modify its own image filesystem unless readOnlyRootFilesystem is explicitly set. The two settings are independent security controls: disabling privilege reduces capabilities, while a read-only rootfs makes the container's filesystem immutable at the runtime level.
- ✗
container.readOnly
Why it's wrong here
container.readOnly is not a defined field in the Kubernetes Container API; the container spec does not include a readOnly property for the root filesystem. A similar term exists only as volumeMounts[].readOnly, which controls whether an individual mounted volume is mounted read-write, but that has no effect on the container's rootfs. Using container.readOnly would not be accepted by the API server and would provide no enforcement, so it is incorrect for this requirement.
- ✓
securityContext.readOnlyRootFilesystem
Why this is correct
Set securityContext.readOnlyRootFilesystem: true at the container level (spec.containers[].securityContext) to instruct the container runtime to mount the container's root filesystem as read-only. This prevents processes in the container from writing to the image's filesystem, though writable volumes such as emptyDir or persistentVolumeClaims remain writable if mounted. It is the only field listed that directly enforces a read-only root filesystem, and it must be repeated for every container that needs this protection.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.