Courseiva
System Hardening →hardMultiple Choice

CKS System Hardening Practice Question

An attacker exploited a container escape vulnerability. The team wants to mitigate such attacks by restricting containers from accessing the host's kernel capabilities. Which set of capabilities should be dropped from all containers?

⚠ Common exam trap

CNCF often tests the misconception that all capabilities are equally dangerous, but the trap here is that candidates may choose networking or file capabilities (options B, C, D) because they sound security-relevant, while the actual escape vector relies on the three kernel-focused capabilities in option A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SYS_ADMIN, SYS_MODULE, SYS_PTRACE

SYS_ADMIN, SYS_MODULE, and SYS_PTRACE are the most dangerous capabilities that enable container escape. SYS_ADMIN grants broad administrative privileges (e.g., mounting filesystems, accessing /proc/1/environ), SYS_MODULE allows loading kernel modules, and SYS_PTRACE permits tracing processes outside the container. Dropping these three capabilities is a key mitigation against kernel-level escapes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SYS_ADMIN, SYS_MODULE, SYS_PTRACE

    Why this is correct

    These capabilities permit privileged kernel operations: SYS_ADMIN enables mount and namespace manipulation, SYS_MODULE loads kernel modules, and SYS_PTRACE inspects other processes. Dropping them removes the primitives container escapes rely on, satisfying the stem's requirement to restrict host kernel access.

  • ✗

    CHOWN, DAC_OVERRIDE, FOWNER

    Why it's wrong here

    CHOWN, DAC_OVERRIDE and FOWNER concern file ownership and bypassing filesystem permission checks, which do not grant the kernel-level access a container escape requires. It is tempting because they are commonly dropped in hardened profiles, and doing so is correct when the aim is limiting file permission manipulation rather than kernel capabilities.

  • ✗

    KILL, SETPCAP, SYS_CHROOT

    Why it's wrong here

    KILL, SETPCAP and SYS_CHROOT relate to signalling processes, altering capability sets and changing root directories, none of which are the privileged kernel operations exploited during a container escape. It is tempting because they appear in default Docker capability lists, and dropping them is correct when tightening general process and filesystem privileges.

  • ✗

    NET_RAW, NET_ADMIN, NET_BIND_SERVICE

    Why it's wrong here

    Dropping these three network capabilities leaves kernel-level escape vectors such as SYS_ADMIN, SYS_PTRACE and SYS_MODULE intact, so host kernel access remains possible. It is tempting because these capabilities are commonly dropped for network hardening, which is the correct choice when the goal is limiting network attack surface, not kernel escapes.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.