Be able to read a Dockerfile or Kubernetes manifest and choose the control that actually reduces host-kernel or credential exposure. The single most important thing: understand that image layers and default cluster permissions persist, so secrets and privilege must be removed at build time and enforced at runtime.
Start practicing
Container Security — choose a session length
Free · No account required
Domain overview
This domain covers securing containerized workloads and orchestrators on Linux hosts. GSEC questions present Dockerfiles, Kubernetes manifests, and multi-tenant cluster scenarios, then ask you to pick the control that best limits blast radius, protects the host kernel, or prevents credential exposure in images and running pods.
Exam objectives
Applying Kubernetes Pod Security Standards, seccomp, AppArmor, and read-only root filesystems to limit container privilege
Using Dockerfile multi-stage builds, .dockerignore, and non-root USER to keep secrets and build artifacts out of images
Configuring Kubernetes RBAC, NetworkPolicy, and service accounts to isolate multi-tenant namespaces and restrict kubelet access
Hardening the container runtime with user namespaces, dropped Linux capabilities, and rootless or gVisor sandboxing
Believing deleting a secret in a later Dockerfile layer removes it; earlier layers still contain the credential and remain pullable.
Assuming namespace separation alone isolates tenants, while default service accounts, hostPath mounts, or missing NetworkPolicy still allow lateral access.
Confusing image scanning with runtime protection; a clean scan does not stop a compromised container from abusing host kernel interfaces.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An enterprise development team is designing a Kubernetes cluster deployment where application containers frequently interact with cloud provider APIs. To minimize security blast radius, which architectural practice provides the most effective credential isolation per pod?
2A security engineer wants to ensure that container images are not modified after they are built and pushed to a registry. Which mechanism provides the strongest assurance of image integrity and authenticity?
3When designing a secure container orchestration strategy, which approach best minimizes the impact of a compromised container on the host kernel?
4Which of the following is the most effective way to prevent secrets (such as API keys) from being leaked via container images?
5Refer to the exhibit. What is the security impact of the provided Kubernetes security context configuration?
6A GSEC consultant is hardening a Kubernetes cluster that runs multi-tenant workloads. A developer reports that a pod in the tenants namespace was able to read the contents of the kubelet's host filesystem at /var/lib/kubelet. The pod spec includes hostPath: {path: /var/lib/kubelet, type: Directory} under volumes and mounts it at /host. The cluster has Pod Security Admission enabled with the restricted profile enforced cluster-wide, but the tenants namespace was labeled pod-security.kubernetes.io/enforce: privileged to unblock a legacy job. Which action most directly closes this exposure?
7A GSEC candidate is reviewing a Docker Compose file for a web application. The file includes a service definition that mounts the Docker socket into the container. What is the primary security risk of this configuration?
8A security analyst is examining a Kubernetes Pod specification that includes the following securityContext: runAsUser: 0. What is the security implication of this setting?
9A security engineer is hardening a Kubernetes cluster that runs multi-tenant workloads. Several pods have been observed running as the root user inside their containers, which the engineer wants to prevent. The engineer applies a Pod Security Admission (PSA) label to the namespace that enforces the 'restricted' profile. Which of the following best describes the enforcement action taken by the 'restricted' profile when a pod violates its policy?
10A developer is building a container image for a Python web application. During review, a security engineer notices the Dockerfile copies a .env file containing database credentials into the image and deletes it in a later RUN instruction. The engineer explains that this pattern still leaks the credentials. Which of the following best explains why the credentials remain exposed in the final image?
11A platform team runs a Kubernetes cluster where a container was compromised through a remote code execution flaw in a web application. The attacker attempted to read the service account token, query the API server, and list secrets in the namespace. The team wants to reduce the impact of such a compromise in the future. Which of the following changes most directly limits what the compromised pod's service account can do against the API server?
12A security engineer is evaluating a container runtime for a production Kubernetes cluster. The requirement is that the runtime must not share the host kernel with containers, providing stronger isolation than standard runc-based containers. Which of the following runtimes best satisfies this requirement?
13A GSEC analyst is reviewing the deployment pipeline for a containerized Node.js service. The Dockerfile contains a layer that runs `curl -fsSL https://example.com/install.sh | sh` during the build, before the image is pushed to an internal registry. The registry enforces vulnerability scanning, and the image is deployed to a Kubernetes cluster with a restrictive NetworkPolicy. Which of the following is the primary supply chain risk introduced by this Dockerfile instruction?
Be able to read a Dockerfile or Kubernetes manifest and choose the control that actually reduces host-kernel or credential exposure. The single most important thing: understand that image layers and default cluster permissions persist, so secrets and privilege must be removed at build time and enforced at runtime.
The Courseiva GSEC question bank contains 13 questions in the Container Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Container Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included