CKS System Hardening Practice Question
An attacker exploited a container escape vulnerability. The team wants to mitigate such attacks by restricting containers from accessing the host's kernel capabilities. Which set of capabilities should be dropped from all containers?
⚠ Common exam trap
CNCF often tests the misconception that all capabilities are equally dangerous, but the trap here is that candidates may choose networking or file capabilities (options B, C, D) because they sound security-relevant, while the actual escape vector relies on the three kernel-focused capabilities in option A.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SYS_ADMIN, SYS_MODULE, SYS_PTRACE
SYS_ADMIN, SYS_MODULE, and SYS_PTRACE are the most dangerous capabilities that enable container escape. SYS_ADMIN grants broad administrative privileges (e.g., mounting filesystems, accessing /proc/1/environ), SYS_MODULE allows loading kernel modules, and SYS_PTRACE permits tracing processes outside the container. Dropping these three capabilities is a key mitigation against kernel-level escapes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SYS_ADMIN, SYS_MODULE, SYS_PTRACE
Why this is correct
These capabilities permit privileged kernel operations: SYS_ADMIN enables mount and namespace manipulation, SYS_MODULE loads kernel modules, and SYS_PTRACE inspects other processes. Dropping them removes the primitives container escapes rely on, satisfying the stem's requirement to restrict host kernel access.
- ✗
CHOWN, DAC_OVERRIDE, FOWNER
Why it's wrong here
CHOWN, DAC_OVERRIDE and FOWNER concern file ownership and bypassing filesystem permission checks, which do not grant the kernel-level access a container escape requires. It is tempting because they are commonly dropped in hardened profiles, and doing so is correct when the aim is limiting file permission manipulation rather than kernel capabilities.
- ✗
KILL, SETPCAP, SYS_CHROOT
Why it's wrong here
KILL, SETPCAP and SYS_CHROOT relate to signalling processes, altering capability sets and changing root directories, none of which are the privileged kernel operations exploited during a container escape. It is tempting because they appear in default Docker capability lists, and dropping them is correct when tightening general process and filesystem privileges.
- ✗
NET_RAW, NET_ADMIN, NET_BIND_SERVICE
Why it's wrong here
Dropping these three network capabilities leaves kernel-level escape vectors such as SYS_ADMIN, SYS_PTRACE and SYS_MODULE intact, so host kernel access remains possible. It is tempting because these capabilities are commonly dropped for network hardening, which is the correct choice when the goal is limiting network attack surface, not kernel escapes.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.