Which THREE of the following are recommended incident response steps when a container is compromised?
Using `kubectl cp` to copy the container’s filesystem is a forensically sound step because it preserves the writable layer, arbitrary files, and binaries without altering the running state. This offline copy lets you analyze the image, look for persistence mechanisms (e.g., cron jobs, backdoors), and inspect configuration files while the container remains responsive. Because `kubectl cp` reads the live filesystem, it is non-destructive and is a best practice before any termination decision. It also gives you a baseline for detecting changes if you later compare with the original image.
Why this answer
Option B is correct because copying the container's filesystem with kubectl cp preserves volatile evidence for offline forensic analysis before the container is destroyed or restarted. Option C is correct because kubectl logs captures the container's stdout/stderr output, which may contain indicators of compromise, attacker commands, or error traces useful for scoping the incident. Option D is correct because applying a NetworkPolicy to the pod isolates it from other workloads, limiting lateral movement and exfiltration while still keeping the container alive for investigation.
Option A is wrong because ignoring a compromise allows the attacker to persist and expand access. Option E is wrong because immediately terminating the pod destroys volatile evidence such as memory, running processes, and network connections, and may trigger automated redeployment that erases the compromised instance before it can be examined.
Exam trap
The trap is choosing to immediately terminate the pod as a containment step, but that destroys evidence; the correct approach is to isolate and preserve first.