Courseiva
System Hardening →hardMultiple Select

CKS System Hardening Practice Question

A security auditor recommends limiting the use of host namespaces in pods. Which THREE of the following fields, if set to true, expose the host namespace to a container?

⚠ Common exam trap

CNCF often tests the distinction between actual Pod spec fields (`hostPID`, `hostIPC`, `hostNetwork`) and non-existent or runtime-specific fields like `hostFS` or `hostUsers`, which candidates might confuse with host namespace options.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

hostPID

Setting `hostPID: true` in a Pod spec allows the container to share the host's process ID namespace. This means the container can see and interact with all processes running on the host node, which breaks process isolation and can lead to privilege escalation or information leakage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    hostPID

    Why this is correct

    Setting hostPID: true mounts the host's PID namespace into the container, allowing it to see all processes running on the node, including those of other pods and system daemons. This breaks namespace isolation and creates a severe privilege escalation risk because the container could discover secrets in process arguments or signal critical system processes. It should only be used in highly trusted, admin-controlled pods.

  • ✓

    hostIPC

    Why this is correct

    hostIPC: true grants the container access to the host's IPC namespace, which includes System V IPC objects and POSIX message queues used by other workloads and node-level services. An attacker in such a container could read or tamper with inter-process communication data, potentially extracting sensitive information or disrupting other components. Pod Security Standards by default disallow sharing the host IPC namespace to preserve workload isolation.

  • ✗

    hostFS

    Why it's wrong here

    hostFS is not a real field in the Kubernetes Pod API; there is no such setting to directly mount the root filesystem of the host. The intended way to expose host filesystem content is through the hostPath volume type, which mounts a specific host directory or file into the pod. Unlike a hypothetical hostFS field, hostPath is explicit about the path and requires a corresponding volume and mount configuration.

  • ✗

    hostUsers

    Why it's wrong here

    hostUsers is not a valid field in the Kubernetes pod spec; nothing like it exists to control whether a pod shares the host's user namespace. User namespace remapping is a low-level runtime feature (e.g., in containerd or CRI-O) or can be approximated through SecurityContext settings such as runAsUser, runAsNonRoot, and supplemental groups. Treating hostUsers as a real option is a misconception that could lead to ineffective security policies.

  • ✓

    hostNetwork

    Why this is correct

    hostNetwork: true removes network namespace isolation, placing the container directly on the host's network stack, so it can bind to any host port and access the node's network services and routing tables. This is often required for infrastructure pods like kube-proxy or CNI agents, but it bypasses Kubernetes NetworkPolicies and makes the pod indistinguishable from host processes. The security impact is high, so hardened clusters typically restrict hostNetwork via admission policies.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.