Courseiva
System Hardening →hardMultiple Select

CKS System Hardening Practice Question

Which THREE of the following are best practices for minimizing host access from containers to reduce the attack surface? (Select three.)

⚠ Common exam trap

CNCF often tests the distinction between host access (namespace sharing) and host exposure (port mapping or resource limits), so candidates may mistakenly select options like hostPort or swap disabling as host access controls when they are actually about network exposure or system performance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Avoid setting hostPID to true

Setting hostPID to true allows a container to share the host's process ID namespace, enabling it to see all host processes and potentially access sensitive information or perform privilege escalation. Avoiding this setting reduces the attack surface by preventing containers from interacting with host-level processes, which is a key principle of namespace isolation in Kubernetes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Avoid setting hostPID to true

    Why this is correct

    Setting hostPID to true places the container directly in the host's process ID namespace, letting it list and signal every process running on the node. An attacker who compromises such a container can inspect /proc entries for sensitive host processes, inject signals, or potentially escalate privileges. Therefore, avoiding hostPID is a fundamental pod security practice to preserve process isolation.

  • ✓

    Avoid setting hostNetwork to true

    Why this is correct

    hostNetwork exposes the container to the node's full network stack, allowing it to bind to arbitrary host ports, observe raw network traffic, and access services listening on localhost. This dramatically enlarges the attack surface and can turn a breach into immediate node-level network compromise. Keeping hostNetwork disabled ensures the container remains inside a separate network namespace, where it only sees its own interfaces and can be controlled by network policies.

  • ✓

    Avoid setting hostIPC to true

    Why this is correct

    hostIPC grants the pod access to the host's inter-process communication resources, including shared memory segments, semaphores, and message queues. Malicious containers could then read or modify data used by other host processes, leading to data corruption or credential theft. It's a lesser-known isolation boundary, but equally dangerous, so it should never be enabled without an explicit and well-justified need.

  • ✗

    Disable swap on nodes

    Why it's wrong here

    Disabling swap on nodes is a common server hardening practice that prevents the kernel from paging memory to disk, which can reduce the risk of sensitive data ending up in swap files. However, it is a node-level configuration independent of container namespaces and does nothing to limit a container's direct access to host resources. As such, it is not a pod-level best practice for minimizing host access from within containers.

  • ✗

    Avoid using hostPort in container port mappings

    Why it's wrong here

    Avoiding hostPort in container port mappings restricts exposure of pod services to the host's IP address, thereby preventing port conflicts and reducing the node's external network footprint. Unlike hostNetwork, hostPort still confines the container to its own network namespace, so it does not grant any additional host process or namespace access. It's a reasonable security consideration, but in the context of minimizing host access, it is not one of the three defining controls.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which of the following host access settings should be avoided to minimize the attack surface from containers? (Select the setting that increases risk the most.)

medium
  • ✓ A.hostPID: true
  • B.securityContext: capabilities: drop: ["ALL"]
  • C.readOnlyRootFilesystem: true
  • D.resources: limits: memory: "512Mi"

Why A: Setting `hostPID: true` allows a container to share the host's process ID namespace, enabling it to see all processes running on the host. This breaks the fundamental isolation that containers should provide, giving a compromised container direct visibility into host processes and the ability to potentially interact with them (e.g., sending signals). This significantly increases the attack surface and is the most dangerous setting among the options.

Variation 2. Which of the following host access settings should be disabled to reduce the attack surface of a container?

easy
  • A.hostNetwork: true
  • B.hostPID: true
  • C.hostIPC: true
  • ✓ D.hostPID: false

Why D: Setting `hostPID: false` explicitly disables the container's access to the host's process ID namespace, which reduces the attack surface by preventing the container from seeing or interacting with host processes. In Kubernetes, when `hostPID` is set to `true`, the container shares the host's PID namespace, allowing it to potentially escalate privileges or interfere with other workloads. Disabling this setting (i.e., `false`) is a recommended security best practice to enforce process isolation.

Variation 3. An administrator wants to prevent a container from accessing the host's network. Which pod security context field should be set to false?

easy
  • A.hostIPC
  • B.privileged
  • C.hostPID
  • ✓ D.hostNetwork

Why D: The `hostNetwork` field in the Pod Security Context, when set to `true`, allows the container to use the host's network namespace directly, bypassing the pod's own network stack. Setting it to `false` (the default) ensures the container uses an isolated network namespace, preventing direct access to host network interfaces, iptables rules, and network services. This is the correct field to disable to meet the requirement of preventing container access to the host's network.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.