CKS System Hardening Practice Question
Which of the following is correct about dropping the 'NET_RAW' capability?
⚠ Common exam trap
CNCF often tests the misconception that 'ping' requires `NET_RAW`, but in modern Linux, ping can use a privileged datagram socket (ICMP_ECHO via SOCK_DGRAM) or setuid, so dropping `NET_RAW` does not always break ping.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It prevents the container from creating raw sockets, which can be used for packet crafting attacks
The `NET_RAW` capability controls access to raw and packet sockets (AF_PACKET, SOCK_RAW). Dropping it prevents the container from creating raw sockets, which are often used for crafting custom packets, performing ARP spoofing, or launching other network-layer attacks. This is a key hardening measure to reduce the container's ability to manipulate network traffic at the low level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It prevents the container from binding to a privileged port (<1024)
Why it's wrong here
Dropping CAP_NET_RAW has no bearing on a container's ability to bind to privileged ports below 1024. In Linux, binding to ports <1024 is governed by CAP_NET_BIND_SERVICE, a separate capability checked at bind() time for TCP/UDP sockets. A container with NET_RAW removed but CAP_NET_BIND_SERVICE present can still listen on port 80 or 443. Thus, this option confuses socket-level privileges with port-access controls.
- ✗
It prevents the container from using the 'ping' command
Why it's wrong here
While ping often relies on raw ICMP sockets, and dropping CAP_NET_RAW will frequently break it, that is only an incidental symptom rather than the capability's purpose. CAP_NET_RAW controls the creation of raw sockets for any protocol, enabling packet crafting and sniffing; it is not a 'ping blocker.' Moreover, on kernels with net.ipv4.ping_group_range set to include the container's group, ping can work through unprivileged ICMP datagram sockets even without CAP_NET_RAW. So this answer mistakes a side effect for the actual security function.
- ✓
It prevents the container from creating raw sockets, which can be used for packet crafting attacks
Why this is correct
CAP_NET_RAW governs the ability to create raw sockets via socket(AF_INET, SOCK_RAW, protocol), which allows a process to craft arbitrary IP packets, spoof addresses, and forge protocol headers. Dropping this capability prevents such packet crafting attacks and also stops raw-socket packet sniffing on the host network, substantially reducing attack surface. Because normal applications use SOCK_STREAM or SOCK_DGRAM, their TCP/UDP traffic is unaffected, making this a precise least-privilege control.
- ✗
It prevents the container from making any network connections
Why it's wrong here
Removing CAP_NET_RAW does not disable ordinary networking: a container can still create sockets of type SOCK_STREAM and SOCK_DGRAM, which the kernel fully manages and which require no raw-packet capability. Dropping NET_RAW leaves network interfaces, IP addressing, and routing intact, so outbound HTTPS, DNS, and inbound connections continue to work. The statement is wrong because it equates raw socket creation with the entire network stack, ignoring that normal communication uses protocol-specific, non-raw sockets.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.