Courseiva
System Hardening →hardMultiple Choice

CKS System Hardening Practice Question

A pod runs with 'hostNetwork: true' and 'hostPID: true'. Which security concern is MOST directly increased?

⚠ Common exam trap

The trap here is that candidates focus on the network-related concern (sniffing traffic) because `hostNetwork` is more obvious, but they overlook that `hostPID` enables direct process manipulation, which is a more severe security risk for container escape.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The container can access host processes and potentially escape

Setting `hostNetwork: true` and `hostPID: true` in a pod grants the container direct access to the host's network namespace and process namespace. With `hostPID: true`, the container can see all host processes (e.g., via `ps aux`) and potentially interact with them using system calls like `ptrace`, which could allow escaping the container by injecting code into a host process. This combination directly increases the risk of container breakout, making A the most significant security concern.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The container can access host processes and potentially escape

    Why this is correct

    With hostPID: true, the container shares the host's PID namespace, so it can enumerate and interact with every host process through /proc. If the container runs as root or has CAP_SYS_PTRACE, it can ptrace host processes, read their memory, inject signals, or extract credentials. This visibility drastically lowers the barrier to a container escape because a single kernel exploit or misconfiguration that gives code execution inside the container can be leveraged against host-level processes directly, rather than being confined to the container's own PID namespace.

  • ✗

    The container can modify iptables rules

    Why it's wrong here

    HostNetwork: true only places the container into the host's network namespace, meaning it sees the host's interfaces and IP stack. Modifying iptables rules requires the NET_ADMIN capability (or being privileged), which is not granted by setting hostNetwork alone. Without that capability, the container's process cannot interact with netfilter rules, even though it shares the host network stack. hostPID is irrelevant here because process namespace sharing does not confer network administration privileges.

  • ✗

    The container can sniff network traffic of other pods

    Why it's wrong here

    HostNetwork: true lets the container bind to and observe the host's network interfaces, but it does not automatically enable sniffing of other pods' traffic. Capturing traffic typically requires CAP_NET_RAW (to use raw sockets) and appropriate network topology; even with that capability, existing iptables rules, network policies, or container network isolation may block such activity. hostPID is about process visibility, not network packet capture, so this option conflates two distinct namespace effects and overstates the sniffing capability.

  • ✗

    The container can mount the host filesystem

    Why it's wrong here

    To mount the host filesystem, a container needs an explicit hostPath volume mounted into its filesystem, or it must be privileged and able to manipulate the host's device nodes and cgroups. Neither hostNetwork nor hostPID provides any filesystem access by itself. These settings affect network and process namespaces respectively, while filesystem access is governed by volume mounts, capabilities, and security context settings such as allowPrivilegeEscalation and readOnlyRootFilesystem.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A pod spec includes 'hostPID: true' and 'hostNetwork: true'. What security concern does this raise?

medium
  • A.The container can use the host's GPU and other devices
  • ✓ B.The container can see all host processes and access the host network namespace, increasing the risk of privilege escalation
  • C.The container can read and write to the host filesystem
  • D.The container cannot use a securityContext

Why B: Setting `hostPID: true` allows the container to see all processes running on the host, which can leak sensitive information and enable process injection. Setting `hostNetwork: true` gives the container direct access to the host's network namespace, bypassing network policies and potentially allowing the container to bind to privileged ports or sniff traffic. Together, these settings significantly increase the attack surface and risk of privilege escalation or host compromise.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.