Courseiva
System Hardening →hardMultiple Choice

CKS System Hardening Practice Question

A Kubernetes cluster uses containerd as the container runtime. The security team wants to restrict a specific container so it cannot create raw network packets. The container image runs as root and the Pod specification does not drop any capabilities. Which Linux capability should be dropped from the container's securityContext to prevent raw packet creation while still allowing binding to privileged ports?

⚠ Common exam trap

A common mix-up: candidates confuse NET_RAW with NET_ADMIN; NET_RAW specifically governs raw sockets, while NET_ADMIN covers broader network configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NET_RAW

The NET_RAW capability is what allows a process to create raw sockets and craft raw network packets. Dropping NET_RAW from the container's securityContext removes this ability while preserving NET_BIND_SERVICE so the container can still bind to privileged ports. This is the least-privilege approach: it targets exactly the unwanted capability without removing unrelated networking permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    NET_RAW

    Why this is correct

    NET_RAW allows the creation of raw sockets, which are required to craft raw network packets. Dropping NET_RAW removes this ability while leaving other networking capabilities such as NET_BIND_SERVICE intact, so the container can still bind to privileged ports. This directly satisfies the requirement without over-restricting the container.

  • ✗

    NET_BIND_SERVICE

    Why it's wrong here

    NET_BIND_SERVICE allows binding to privileged ports below 1024. The requirement explicitly states that binding to privileged ports must still be allowed, so dropping this capability would break the intended functionality. It also has no effect on creating raw network packets, so it does not address the security concern.

  • ✗

    SYS_ADMIN

    Why it's wrong here

    SYS_ADMIN is a powerful capability covering a wide range of system administration operations, but it is not the specific capability required for raw socket creation. Dropping it would significantly restrict the container without directly preventing raw packet generation. The precise control for raw sockets is a different capability.

  • ✗

    NET_ADMIN

    Why it's wrong here

    NET_ADMIN grants broad network administration privileges including interface configuration, routing, and firewall changes. While it can indirectly affect packet handling, it is not the capability that specifically enables raw packet creation. Dropping NET_ADMIN would remove many legitimate networking functions and does not precisely target the raw socket capability.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.