Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A DevSecOps team runs workloads on a managed Kubernetes service. The security policy states that no pod may run as the root user, that containers must not mount the host filesystem, and that privilege escalation must be blocked. The team wants a control that evaluates pod specifications at admission time and rejects non-compliant pods before they are scheduled, without modifying application code. Which mechanism should the team implement?

⚠ Common exam trap

The trap here is selecting PodSecurityPolicy, which is removed in current Kubernetes, or a runtime tool, which detects rather than prevents non-compliant pods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A validating admission webhook or a Pod Security Admission configuration with the restricted profile enforced

The requirement is admission-time rejection of pods that run as root, mount the host filesystem, or allow privilege escalation. Pod Security Admission with the restricted profile, or a validating admission webhook, evaluates pod specifications before scheduling and rejects non-compliant pods without code changes. Network policies and runtime agents address different layers and cannot prevent the pods from being admitted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A runtime security agent that scans running containers and sends alerts when it detects root processes

    Why it's wrong here

    Runtime detection identifies violations after pods are already running, which is too late to prevent the risk. The policy requires rejection before scheduling, and a detection-only tool does not enforce the restriction. While runtime monitoring is valuable for defense in depth, it does not satisfy the admission-time enforcement requirement and would allow non-compliant pods to run until an alert is triaged.

  • ✗

    A PodSecurityPolicy object bound to the service account used by the workloads

    Why it's wrong here

    PodSecurityPolicy was deprecated in Kubernetes 1.21 and removed in 1.25, so it is not available on current managed Kubernetes versions. Even where it existed, it required careful RBAC binding and was easy to misconfigure. Recommending it for a current cluster is technically inaccurate and would not provide the admission-time enforcement the team needs on a supported platform.

  • ✓

    A validating admission webhook or a Pod Security Admission configuration with the restricted profile enforced

    Why this is correct

    Pod Security Admission is the built-in successor to PodSecurityPolicy and enforces the restricted profile, which requires non-root execution, disallows host filesystem mounts, and blocks privilege escalation. A validating admission webhook can enforce custom policies with greater flexibility. Both evaluate pod specifications at admission time and reject non-compliant pods before scheduling, without requiring application code changes.

  • ✗

    A network policy that denies ingress to the pods from all namespaces except the application namespace

    Why it's wrong here

    Network policies control pod-to-pod network traffic, not the security context of the pod itself. They cannot enforce non-root execution, prevent host filesystem mounts, or block privilege escalation. This control addresses east-west network segmentation and is unrelated to the admission-time pod hardening the policy requires, so it would leave the stated risks unmitigated.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.