CV0-004 Security Practice Question
A DevOps team deploys a containerized application to a Kubernetes cluster. They need to ensure that containers cannot run with privileged access. Which Kubernetes security mechanism should be applied?
⚠ Common exam trap
CV0-004 often tests the confusion between network-level controls (Network Policies) and workload-level privilege controls (Pod Security Standards) — candidates may pick Network Policies thinking they restrict container capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pod Security Standards
Pod Security Standards (PSS) define three profiles — Privileged, Baseline, and Restricted — that control whether pods can run with privileged access, host networking, hostPath volumes, and similar elevated capabilities. Enforcing the Restricted or Baseline profile via Pod Security Admission prevents containers from running privileged. This is the native Kubernetes mechanism for restricting pod-level privileges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Pod Security Standards
Why this is correct
Pod Security Standards define the privileged, baseline and restricted profiles enforced via pod security admission, blocking containers that request privileged mode. This directly satisfies the constraint that containers cannot run with privileged access, unlike RBAC, which governs API permissions rather than pod capabilities.
- ✗
Network policies
Why it's wrong here
Network policies control pod ingress and egress traffic at layers 3 and 4; they cannot prevent a container starting with privileged: true. Pod Security Admission or a securityContext setting privileged: false addresses that. Network policies would be correct where the requirement is segmenting or isolating pod traffic.
- ✗
ConfigMaps
Why it's wrong here
ConfigMaps inject non-confidential configuration data as environment variables or mounted files; they hold no admission or security-context enforcement. Pod Security Admission or a securityContext with privileged: false is required. ConfigMaps would be right where the goal is decoupling configuration from the container image.
- ✗
Service accounts
Why it's wrong here
Service accounts supply an identity for pods to authenticate to the Kubernetes API; they do not constrain container security context. Pod Security Admission or a securityContext with privileged: false enforces the restriction. Service accounts would be right where workloads need scoped API credentials, not privilege enforcement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.