Courseiva
Security →mediumMultiple Choice

CV0-004 Security Practice Question

A DevOps team is deploying containerized applications on Kubernetes. They want to ensure containers do not run with root privileges and that host filesystem access is restricted. Which Kubernetes feature should they use?

⚠ Common exam trap

The trap is conflating network-level controls (Network Policies) or identity controls (Service Accounts) with workload security controls — candidates pick Network Policies because 'restricting access' sounds security-related, but it does not address root privileges or host filesystem mounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pod Security Standards

Pod Security Standards (PSS) define three profiles — Privileged, Baseline, and Restricted — that control whether pods can run as root, use host namespaces, access the host filesystem, or use privileged capabilities. Enforcing the Restricted profile via Pod Security Admission (PSA) directly prevents root execution and restricts hostPath/host filesystem access. This is the native Kubernetes mechanism for pod-level security hardening.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Service accounts

    Why it's wrong here

    Service accounts supply an identity for pods to authenticate to the Kubernetes API; they do not set privilege or filesystem constraints. They are tempting because they relate to pod security, and would be correct when the requirement is granting a workload scoped API access.

  • ✗

    ConfigMaps

    Why it's wrong here

    ConfigMaps inject non-confidential configuration data as environment variables or files; they enforce no privilege or filesystem restrictions. They are tempting because they are a core workload-configuration object, and would be correct when the requirement is decoupling application settings from container images.

  • ✗

    Network policies

    Why it's wrong here

    Network policies control ingress and egress traffic between pods and namespaces at layer 3/4; they cannot prevent root execution or host filesystem mounts. They are tempting because they harden cluster workloads, and would be correct when the requirement is restricting which pods may communicate.

  • ✓

    Pod Security Standards

    Why this is correct

    Pod Security Standards define restricted, baseline and privileged profiles enforced via Pod Security Admission. The restricted profile blocks root execution and host filesystem mounts, directly satisfying both the non-root and host-access constraints without custom policy authoring.

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.