CV0-004 Security Practice Question
A DevOps team is deploying containerized applications on Kubernetes. They want to ensure containers do not run with root privileges and that host filesystem access is restricted. Which Kubernetes feature should they use?
⚠ Common exam trap
The trap is conflating network-level controls (Network Policies) or identity controls (Service Accounts) with workload security controls — candidates pick Network Policies because 'restricting access' sounds security-related, but it does not address root privileges or host filesystem mounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pod Security Standards
Pod Security Standards (PSS) define three profiles — Privileged, Baseline, and Restricted — that control whether pods can run as root, use host namespaces, access the host filesystem, or use privileged capabilities. Enforcing the Restricted profile via Pod Security Admission (PSA) directly prevents root execution and restricts hostPath/host filesystem access. This is the native Kubernetes mechanism for pod-level security hardening.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Service accounts
Why it's wrong here
Service accounts supply an identity for pods to authenticate to the Kubernetes API; they do not set privilege or filesystem constraints. They are tempting because they relate to pod security, and would be correct when the requirement is granting a workload scoped API access.
- ✗
ConfigMaps
Why it's wrong here
ConfigMaps inject non-confidential configuration data as environment variables or files; they enforce no privilege or filesystem restrictions. They are tempting because they are a core workload-configuration object, and would be correct when the requirement is decoupling application settings from container images.
- ✗
Network policies
Why it's wrong here
Network policies control ingress and egress traffic between pods and namespaces at layer 3/4; they cannot prevent root execution or host filesystem mounts. They are tempting because they harden cluster workloads, and would be correct when the requirement is restricting which pods may communicate.
- ✓
Pod Security Standards
Why this is correct
Pod Security Standards define restricted, baseline and privileged profiles enforced via Pod Security Admission. The restricted profile blocks root execution and host filesystem mounts, directly satisfying both the non-root and host-access constraints without custom policy authoring.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.