GSEC Container Security Practice Question
A security engineer is hardening a Kubernetes cluster that runs multi-tenant workloads. Several pods have been observed running as the root user inside their containers, which the engineer wants to prevent. The engineer applies a Pod Security Admission (PSA) label to the namespace that enforces the 'restricted' profile. Which of the following best describes the enforcement action taken by the 'restricted' profile when a pod violates its policy?
⚠ Common exam trap
It's easy for candidates to confuse the audit and warn modes with enforce mode, assuming that a violation only produces a log entry rather than a rejection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The pod is rejected and the API server returns an error, preventing it from being scheduled.
The restricted Pod Security Standard is the most restrictive of the three built-in profiles and enforces controls such as requiring non-root execution, dropping all capabilities, and mandating a seccomp profile. When a namespace enforces this profile, non-compliant pods are denied at admission, directly preventing root-running containers from being scheduled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The pod is rejected and the API server returns an error, preventing it from being scheduled.
Why this is correct
The restricted profile is the most stringent of the Pod Security Standards and directly rejects pods that violate its controls, such as running as root or lacking a seccomp profile. Rejection occurs at admission time, so the non-compliant pod never reaches a node, which directly addresses the engineer's goal of preventing root-running pods.
- ✗
The pod is admitted but an audit annotation is added to the pod's metadata for later review.
Why it's wrong here
This describes the 'audit' mode, not the 'restricted' profile. The restricted profile enforces strict controls and will reject non-compliant pods rather than merely annotating them. Annotations alone do not prevent the pod from running as root, which is the security concern in this scenario.
- ✗
The pod is scheduled but the kubelet forcibly changes the container's user to a non-root UID at runtime.
Why it's wrong here
The kubelet does not rewrite the container's user identity at runtime. User identity is determined by the image's USER instruction or the pod's securityContext. Pod Security Admission operates at the API server admission phase, not by mutating runtime behavior on the node, so this mechanism does not exist.
- ✗
The pod is admitted and a warning is written to the API server logs, but no enforcement action is taken.
Why it's wrong here
This describes the 'warn' mode behavior. The restricted profile in enforce mode does not simply log warnings; it denies the pod. Logging alone would not stop the root-running pods the engineer is trying to eliminate, leaving the multi-tenant cluster exposed to privilege escalation risks.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.