CKS System Hardening Practice Question
A node in your cluster is running unnecessary services that increase the attack surface. Which of the following is the BEST approach to reduce the attack surface on the node?
⚠ Common exam trap
A common mistake in the CKS exam is to focus on network-level controls (firewall, NetworkPolicy) or confinement (AppArmor) rather than disabling the unnecessary service directly. The key is that disabling the service removes the attack surface entirely, whereas blocking or confining still leaves the service running and potentially exploitable through other means.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify and disable unnecessary system services using systemctl or similar tools
The most direct way to reduce the attack surface on a node is to disable unnecessary services that are actively listening or running. Tools like `systemctl disable` or `systemctl stop` permanently turn off services such as `telnet`, `rpcbind`, or `cups`, which are common vectors for exploitation. Simply blocking ports with a firewall (A) leaves the service running and potentially exploitable via localhost or if the firewall is misconfigured, while AppArmor (D) confines but does not remove the service. NetworkPolicies (B) operate at the Kubernetes network layer and cannot control host-level services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a firewall to block all ports except those required
Why it's wrong here
A host firewall (iptables/nftables) filters traffic at the network layer, so blocking all ports except required ones prevents external connections to the unneeded service. However, the process remains running and listening; it can still be reached via localhost, by a compromised pod using host networking, or through a later misconfigured rule. Firewalls are a boundary control, not a remediation for unwanted software, and do not reduce CPU, memory, or vulnerable code exposure.
- ✗
Apply a NetworkPolicy to block traffic to the node
Why it's wrong here
NetworkPolicy is a Kubernetes API object that selects pods via label selectors and namespace scopes, and it is enforced by the CNI plugin for pod-to-pod traffic. Node-level services such as sshd, kubelet, containerd, or an unused daemon are not pods and have no pod Selectors, so a NetworkPolicy cannot target them. Even if a node's service were exposed through a hostPort, NetworkPolicy still does not govern traffic to node IPs; it only controls connections to and from pod IPs.
- ✓
Identify and disable unnecessary system services using systemctl or similar tools
Why this is correct
Disabling and removing unnecessary services with systemctl --now disable and optionally masking their unit files stops the running process and prevents it from starting at boot, eliminating the attack vector at the source. This follows the least functionality principle, which is the correct remediation for unnecessary services. It also frees system resources and reduces the surface available to an attacker who has achieved code execution on the node. For a Kubernetes node, keep only required services such as containerd, kubelet, kube-proxy, and necessary system utilities.
- ✗
Use AppArmor to confine the services
Why it's wrong here
AppArmor (or SELinux) confines a process by enforcing mandatory access control on files, network, capabilities, and other operations, so it limits what the service can do even if it is compromised. However, the service remains alive and accessible, so it can still be exploited for denial of service, resource exhaustion, or to attack other processes if the profile is too permissive. AppArmor is a valuable defense-in-depth measure, but it does not address the core problem that the service should not exist on the node at all.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.