CKS Minimize Microservice Vulnerabilities Practice Question
You need to use gVisor as a container runtime for a set of workloads in the cluster. Which Kubernetes resource must be created to reference the runtime class?
⚠ Common exam trap
Watch out — candidates often confuse creating the RuntimeClass resource with simply setting a field on a Pod, forgetting that the RuntimeClass object must exist in the cluster first, and that gVisor does not require a CRD or kubelet flag.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a RuntimeClass resource with handler: runsc
In Kubernetes, a RuntimeClass resource is used to select a container runtime configuration, such as gVisor. The RuntimeClass must specify the handler field set to 'runsc', which is the gVisor runtime binary. This resource is then referenced by pods via the `runtimeClassName` field to enforce sandboxed isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a RuntimeClass resource with handler: runsc
Why this is correct
A RuntimeClass resource names the runtime handler, here runsc, which the kubelet uses to run matching pods under gVisor. Creating it with handler: runsc registers the sandboxed runtime so pods can select it via runtimeClassName, satisfying the requirement.
- ✗
Set the kubelet runtime flag --runtime-class=gvisor
Why it's wrong here
A kubelet flag cannot select a runtime per workload; RuntimeClass is a cluster-scoped API object referenced by pods. The flag approach suits setting a single default runtime for the whole node, not assigning gVisor to specific workloads.
- ✗
Install a CRD for gVisor
Why it's wrong here
A RuntimeClass object is a built-in Kubernetes resource, not a CRD; creating a CRD adds no runtime handler and gVisor would never be scheduled. CRDs suit extending the API with custom resources, which is the right approach when defining bespoke objects rather than selecting an existing container runtime.
- ✗
Create a Pod with spec.runtimeClassName set to "gvisor"
Why it's wrong here
Creating a Pod with spec.runtimeClassName set to "gvisor" consumes a RuntimeClass rather than defining one; the question asks which resource must be created to reference the runtime, and no RuntimeClass object named "gvisor" exists yet. It is tempting because runtimeClassName is genuinely how workloads select a runtime, which would be correct once the RuntimeClass resource is registered.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.