CKS System Hardening Practice Question
A pod runs with 'hostNetwork: true' and 'hostPID: true'. Which security concern is MOST directly increased?
⚠ Common exam trap
The trap here is that candidates focus on the network-related concern (sniffing traffic) because `hostNetwork` is more obvious, but they overlook that `hostPID` enables direct process manipulation, which is a more severe security risk for container escape.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The container can access host processes and potentially escape
Setting `hostNetwork: true` and `hostPID: true` in a pod grants the container direct access to the host's network namespace and process namespace. With `hostPID: true`, the container can see all host processes (e.g., via `ps aux`) and potentially interact with them using system calls like `ptrace`, which could allow escaping the container by injecting code into a host process. This combination directly increases the risk of container breakout, making A the most significant security concern.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The container can access host processes and potentially escape
Why this is correct
With hostPID: true, the container shares the host's PID namespace, so it can enumerate and interact with every host process through /proc. If the container runs as root or has CAP_SYS_PTRACE, it can ptrace host processes, read their memory, inject signals, or extract credentials. This visibility drastically lowers the barrier to a container escape because a single kernel exploit or misconfiguration that gives code execution inside the container can be leveraged against host-level processes directly, rather than being confined to the container's own PID namespace.
- ✗
The container can modify iptables rules
Why it's wrong here
HostNetwork: true only places the container into the host's network namespace, meaning it sees the host's interfaces and IP stack. Modifying iptables rules requires the NET_ADMIN capability (or being privileged), which is not granted by setting hostNetwork alone. Without that capability, the container's process cannot interact with netfilter rules, even though it shares the host network stack. hostPID is irrelevant here because process namespace sharing does not confer network administration privileges.
- ✗
The container can sniff network traffic of other pods
Why it's wrong here
HostNetwork: true lets the container bind to and observe the host's network interfaces, but it does not automatically enable sniffing of other pods' traffic. Capturing traffic typically requires CAP_NET_RAW (to use raw sockets) and appropriate network topology; even with that capability, existing iptables rules, network policies, or container network isolation may block such activity. hostPID is about process visibility, not network packet capture, so this option conflates two distinct namespace effects and overstates the sniffing capability.
- ✗
The container can mount the host filesystem
Why it's wrong here
To mount the host filesystem, a container needs an explicit hostPath volume mounted into its filesystem, or it must be privileged and able to manipulate the host's device nodes and cgroups. Neither hostNetwork nor hostPID provides any filesystem access by itself. These settings affect network and process namespaces respectively, while filesystem access is governed by volume mounts, capabilities, and security context settings such as allowPrivilegeEscalation and readOnlyRootFilesystem.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A pod spec includes 'hostPID: true' and 'hostNetwork: true'. What security concern does this raise?
medium- A.The container can use the host's GPU and other devices
- ✓ B.The container can see all host processes and access the host network namespace, increasing the risk of privilege escalation
- C.The container can read and write to the host filesystem
- D.The container cannot use a securityContext
Why B: Setting `hostPID: true` allows the container to see all processes running on the host, which can leak sensitive information and enable process injection. Setting `hostNetwork: true` gives the container direct access to the host's network namespace, bypassing network policies and potentially allowing the container to bind to privileged ports or sniff traffic. Together, these settings significantly increase the attack surface and risk of privilege escalation or host compromise.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.