ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A finance startup runs dozens of Linux containers in a managed Kubernetes cluster hosted by a public cloud provider. Management wants an extra layer of defense that will still be effective if an attacker achieves a container breakout at the application layer, but remains confined to the container's user space. The chosen control must explicitly limit which kernel functions the process inside each container can invoke, thereby reducing the blast radius of a compromise. Which hardening action BEST meets this goal?
Place all worker nodes in an isolated private subnet with no inbound Internet access.
Apply fine-grained seccomp and AppArmor profiles to every container to restrict available system calls and kernel capabilities.
Configure an admission controller that rejects any image pulled with the :latest tag.
Mount the host's Docker socket inside each pod so a security scanner can inspect running containers.
Applying seccomp and AppArmor (or SELinux) profiles to each container enforces a whitelist of allowed Linux system calls and capabilities. If an attacker escapes the application but remains inside the container, attempts to invoke disallowed kernel functions-such as loading kernel modules, changing network settings, or escalating privileges-will be blocked, reducing potential impact. Moving worker nodes to a private subnet improves network exposure but does not constrain kernel interactions. Disallowing the :latest tag helps with image provenance yet offers no runtime syscall restriction. Mounting the Docker socket greatly increases risk because it grants containers control over the host daemon, the opposite of the desired effect.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is seccomp and how does it work?
Open an interactive chat with Bash
How does AppArmor enhance security compared to seccomp?
Open an interactive chat with Bash
Why are :latest tags discouraged for container images?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .