CCSP Cloud Platform and Infrastructure Security Practice Question
A DevSecOps team runs workloads on a managed Kubernetes service. The security policy states that no pod may run as the root user, that containers must not mount the host filesystem, and that privilege escalation must be blocked. The team wants a control that evaluates pod specifications at admission time and rejects non-compliant pods before they are scheduled, without modifying application code. Which mechanism should the team implement?
⚠ Common exam trap
The trap here is selecting PodSecurityPolicy, which is removed in current Kubernetes, or a runtime tool, which detects rather than prevents non-compliant pods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A validating admission webhook or a Pod Security Admission configuration with the restricted profile enforced
The requirement is admission-time rejection of pods that run as root, mount the host filesystem, or allow privilege escalation. Pod Security Admission with the restricted profile, or a validating admission webhook, evaluates pod specifications before scheduling and rejects non-compliant pods without code changes. Network policies and runtime agents address different layers and cannot prevent the pods from being admitted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A runtime security agent that scans running containers and sends alerts when it detects root processes
Why it's wrong here
Runtime detection identifies violations after pods are already running, which is too late to prevent the risk. The policy requires rejection before scheduling, and a detection-only tool does not enforce the restriction. While runtime monitoring is valuable for defense in depth, it does not satisfy the admission-time enforcement requirement and would allow non-compliant pods to run until an alert is triaged.
- ✗
A PodSecurityPolicy object bound to the service account used by the workloads
Why it's wrong here
PodSecurityPolicy was deprecated in Kubernetes 1.21 and removed in 1.25, so it is not available on current managed Kubernetes versions. Even where it existed, it required careful RBAC binding and was easy to misconfigure. Recommending it for a current cluster is technically inaccurate and would not provide the admission-time enforcement the team needs on a supported platform.
- ✓
A validating admission webhook or a Pod Security Admission configuration with the restricted profile enforced
Why this is correct
Pod Security Admission is the built-in successor to PodSecurityPolicy and enforces the restricted profile, which requires non-root execution, disallows host filesystem mounts, and blocks privilege escalation. A validating admission webhook can enforce custom policies with greater flexibility. Both evaluate pod specifications at admission time and reject non-compliant pods before scheduling, without requiring application code changes.
- ✗
A network policy that denies ingress to the pods from all namespaces except the application namespace
Why it's wrong here
Network policies control pod-to-pod network traffic, not the security context of the pod itself. They cannot enforce non-root execution, prevent host filesystem mounts, or block privilege escalation. This control addresses east-west network segmentation and is unrelated to the admission-time pod hardening the policy requires, so it would leave the stated risks unmitigated.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.