CKS System Hardening Practice Question
A Kubernetes cluster uses containerd as the container runtime. The security team wants to restrict a specific container so it cannot create raw network packets. The container image runs as root and the Pod specification does not drop any capabilities. Which Linux capability should be dropped from the container's securityContext to prevent raw packet creation while still allowing binding to privileged ports?
⚠ Common exam trap
A common mix-up: candidates confuse NET_RAW with NET_ADMIN; NET_RAW specifically governs raw sockets, while NET_ADMIN covers broader network configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NET_RAW
The NET_RAW capability is what allows a process to create raw sockets and craft raw network packets. Dropping NET_RAW from the container's securityContext removes this ability while preserving NET_BIND_SERVICE so the container can still bind to privileged ports. This is the least-privilege approach: it targets exactly the unwanted capability without removing unrelated networking permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
NET_RAW
Why this is correct
NET_RAW allows the creation of raw sockets, which are required to craft raw network packets. Dropping NET_RAW removes this ability while leaving other networking capabilities such as NET_BIND_SERVICE intact, so the container can still bind to privileged ports. This directly satisfies the requirement without over-restricting the container.
- ✗
NET_BIND_SERVICE
Why it's wrong here
NET_BIND_SERVICE allows binding to privileged ports below 1024. The requirement explicitly states that binding to privileged ports must still be allowed, so dropping this capability would break the intended functionality. It also has no effect on creating raw network packets, so it does not address the security concern.
- ✗
SYS_ADMIN
Why it's wrong here
SYS_ADMIN is a powerful capability covering a wide range of system administration operations, but it is not the specific capability required for raw socket creation. Dropping it would significantly restrict the container without directly preventing raw packet generation. The precise control for raw sockets is a different capability.
- ✗
NET_ADMIN
Why it's wrong here
NET_ADMIN grants broad network administration privileges including interface configuration, routing, and firewall changes. While it can indirectly affect packet handling, it is not the capability that specifically enables raw packet creation. Dropping NET_ADMIN would remove many legitimate networking functions and does not precisely target the raw socket capability.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.