Courseiva
Security →hardMultiple Choice

CV0-004 Security Practice Question

A DevOps team deploys a containerized application to a Kubernetes cluster. They need to ensure that containers cannot run with privileged access. Which Kubernetes security mechanism should be applied?

⚠ Common exam trap

CV0-004 often tests the confusion between network-level controls (Network Policies) and workload-level privilege controls (Pod Security Standards) — candidates may pick Network Policies thinking they restrict container capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pod Security Standards

Pod Security Standards (PSS) define three profiles — Privileged, Baseline, and Restricted — that control whether pods can run with privileged access, host networking, hostPath volumes, and similar elevated capabilities. Enforcing the Restricted or Baseline profile via Pod Security Admission prevents containers from running privileged. This is the native Kubernetes mechanism for restricting pod-level privileges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Pod Security Standards

    Why this is correct

    Pod Security Standards define the privileged, baseline and restricted profiles enforced via pod security admission, blocking containers that request privileged mode. This directly satisfies the constraint that containers cannot run with privileged access, unlike RBAC, which governs API permissions rather than pod capabilities.

  • ✗

    Network policies

    Why it's wrong here

    Network policies control pod ingress and egress traffic at layers 3 and 4; they cannot prevent a container starting with privileged: true. Pod Security Admission or a securityContext setting privileged: false addresses that. Network policies would be correct where the requirement is segmenting or isolating pod traffic.

  • ✗

    ConfigMaps

    Why it's wrong here

    ConfigMaps inject non-confidential configuration data as environment variables or mounted files; they hold no admission or security-context enforcement. Pod Security Admission or a securityContext with privileged: false is required. ConfigMaps would be right where the goal is decoupling configuration from the container image.

  • ✗

    Service accounts

    Why it's wrong here

    Service accounts supply an identity for pods to authenticate to the Kubernetes API; they do not constrain container security context. Pod Security Admission or a securityContext with privileged: false enforces the restriction. Service accounts would be right where workloads need scoped API credentials, not privilege enforcement.

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.