CKS Monitoring, Logging and Runtime Security Practice Question
You want to ensure that a container's root filesystem is immutable. Which field in the Pod spec should you set?
⚠ Common exam trap
CKS often tests the distinction between read-only root filesystem and read-only volume mounts, and candidates may incorrectly choose volumeMounts readOnly thinking it applies to the entire container.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
spec.containers[].securityContext.readOnlyRootFilesystem
The correct field to make a container's root filesystem immutable is 'spec.containers[].securityContext.readOnlyRootFilesystem'. When set to true, this mounts the container's root filesystem as read-only, preventing any writes to the filesystem. This is a key security measure to prevent runtime modifications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
spec.containers[].securityContext.privileged
Why it's wrong here
Setting spec.containers[].securityContext.privileged to true grants the container all available Linux capabilities and disables security features like seccomp and AppArmor, but it does not change how the root filesystem is mounted. The container's root filesystem remains writable because privilege escalation is about access control and device exposure, not about the mount flags (e.g., ro) applied to the rootfs. Therefore, privileged mode does not make the root filesystem immutable and is not a valid solution for this requirement.
- ✗
spec.hostNetwork
Why it's wrong here
spec.hostNetwork: true places the container directly in the host's network namespace, so it shares the host's IP address and network stack, which affects network isolation and port binding. This field has absolutely no effect on the container's filesystem mount options, including the root filesystem; the rootfs is still mounted with its normal writable layer unless explicitly overridden elsewhere. Since hostNetwork only changes network behavior, it cannot enforce or provide a read-only root filesystem, making it an invalid choice.
- ✓
spec.containers[].securityContext.readOnlyRootFilesystem
Why this is correct
Setting spec.containers[].securityContext.readOnlyRootFilesystem to true instructs the container runtime to mount the container's root filesystem as read-only, meaning the image's root filesystem and any upper writable layer become immutable at the mount level. When this is set, any attempt to write to directories other than explicitly mounted volumes (such as emptyDir or persistent volumes) fails with an error, preventing tampering with binaries, libraries, or configuration files. This is the direct and intended securityContext field to enforce root filesystem immutability for a container, though you may need to mount writable volumes for runtime data like /tmp.
- ✗
spec.containers[].volumeMounts[].readOnly
Why it's wrong here
spec.containers[].volumeMounts[].readOnly is a field on a mount entry that only controls whether a specific, explicitly mounted volume is accessible read-only. For example, you might set readOnly: true when mounting a ConfigMap or Secret so its contents cannot be modified from the container, but this does not affect the container's root filesystem itself. The rootfs, which contains the operating system and application binaries, remains writable unless separately configured with readOnlyRootFilesystem, so this option is insufficient for making the root filesystem immutable.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. To ensure a container's filesystem is read-only, which field should be set to 'true' in the container spec?
easy- ✓ A.securityContext.readOnlyRootFilesystem
- B.securityContext.runAsNonRoot
- C.container.fsGroup
- D.podSpec.containers.readonly
Why A: The `securityContext.readOnlyRootFilesystem` field, when set to `true`, mounts the container's root filesystem as read-only. This prevents any writes to the container's filesystem, enhancing security by making it immutable. It is the correct field to ensure a read-only filesystem.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.