19+ practice questions focused on Container Security — one of the most tested topics on the GIAC Security Essentials exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Container Security PracticeWhich TWO of the following configurations are considered best practices for securing the Docker daemon?
Explanation: Securing the Docker daemon is critical because it runs with root privileges and serves as a primary target for host escape attacks. Restricting network access via TLS and enforcing user namespaces prevents attackers from gaining full host access even if a container is compromised. These configurations create a boundary between the container runtime and the host kernel, significantly reducing the attack surface for privilege escalation attempts.
Refer to the exhibit. An engineer is reviewing a Dockerfile for a microservice. Which security issue is present in this configuration?
Explanation: The current configuration installs software as root before switching users. While the USER instruction is present, the image maintains root-owned files or potentially leftover build artifacts from the initial layers. A secure approach involves multi-stage builds to discard build tools and ensure the final image contains minimal layers, reducing the attack surface. Leaving unnecessary binaries like 'curl' increases the potential utility for an attacker during a post-exploitation phase.
Which THREE of the following are primary components of a comprehensive container security strategy?
Explanation: A robust container security strategy must address the entire lifecycle, including the build process, registry management, and runtime protection. By integrating security into the CI/CD pipeline, enforcing access controls on registries, and monitoring runtime behavior for anomalies, organizations can detect threats at multiple stages. These layers ensure that if one control fails, others remain to provide visibility and prevent successful exploitation by malicious actors.
A GSEC analyst is reviewing a Kubernetes Deployment manifest for an internet-facing payment service. The pod spec sets allowPrivilegeEscalation to false, runAsNonRoot to true, and drops all Linux capabilities, but the container image is tagged myregistry/paymentsvc:latest and the imagePullPolicy is left at its default. The analyst wants to harden the workload so that a compromised registry account cannot silently swap in a malicious image on the next pod restart. Which change best mitigates this supply-chain risk?
Explanation: A mutable tag such as latest resolves at pull time to whatever the registry currently serves, so an attacker who compromises registry credentials can replace the reviewed image with a backdoored one and the cluster will run it on the next restart. Referencing the image by its sha256 digest makes the manifest point to an exact, content-addressed set of layers, and setting imagePullPolicy to Always ensures the kubelet re-resolves that digest rather than relying on a cached copy.
A security engineer is configuring a Kubernetes cluster and wants to enforce that all pods must run with a read-only root filesystem. Which Kubernetes admission controller should be used to validate this requirement?
Explanation: Pod Security Admission (PSA) is the current built-in mechanism to enforce Pod Security Standards at the namespace level. The Restricted profile requires containers to run with a read-only root filesystem, among other restrictions. By labeling a namespace with pod-security.kubernetes.io/enforce: restricted, PSA will reject pods that do not comply.
+14 more Container Security questions available
Practice all Container Security questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Container Security. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Container Security questions on the GSEC frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Container Security is tested as part of the GIAC Security Essentials blueprint. Practicing with targeted Container Security questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GSEC practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Container Security is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Container Security practice session with instant scoring and detailed explanations.
Start Container Security Practice →