CKS System Hardening Practice Question
Which THREE of the following are best practices for minimizing host access from containers to reduce the attack surface? (Select three.)
⚠ Common exam trap
CNCF often tests the distinction between host access (namespace sharing) and host exposure (port mapping or resource limits), so candidates may mistakenly select options like hostPort or swap disabling as host access controls when they are actually about network exposure or system performance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Avoid setting hostPID to true
Setting hostPID to true allows a container to share the host's process ID namespace, enabling it to see all host processes and potentially access sensitive information or perform privilege escalation. Avoiding this setting reduces the attack surface by preventing containers from interacting with host-level processes, which is a key principle of namespace isolation in Kubernetes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Avoid setting hostPID to true
Why this is correct
Setting hostPID to true places the container directly in the host's process ID namespace, letting it list and signal every process running on the node. An attacker who compromises such a container can inspect /proc entries for sensitive host processes, inject signals, or potentially escalate privileges. Therefore, avoiding hostPID is a fundamental pod security practice to preserve process isolation.
- ✓
Avoid setting hostNetwork to true
Why this is correct
hostNetwork exposes the container to the node's full network stack, allowing it to bind to arbitrary host ports, observe raw network traffic, and access services listening on localhost. This dramatically enlarges the attack surface and can turn a breach into immediate node-level network compromise. Keeping hostNetwork disabled ensures the container remains inside a separate network namespace, where it only sees its own interfaces and can be controlled by network policies.
- ✓
Avoid setting hostIPC to true
Why this is correct
hostIPC grants the pod access to the host's inter-process communication resources, including shared memory segments, semaphores, and message queues. Malicious containers could then read or modify data used by other host processes, leading to data corruption or credential theft. It's a lesser-known isolation boundary, but equally dangerous, so it should never be enabled without an explicit and well-justified need.
- ✗
Disable swap on nodes
Why it's wrong here
Disabling swap on nodes is a common server hardening practice that prevents the kernel from paging memory to disk, which can reduce the risk of sensitive data ending up in swap files. However, it is a node-level configuration independent of container namespaces and does nothing to limit a container's direct access to host resources. As such, it is not a pod-level best practice for minimizing host access from within containers.
- ✗
Avoid using hostPort in container port mappings
Why it's wrong here
Avoiding hostPort in container port mappings restricts exposure of pod services to the host's IP address, thereby preventing port conflicts and reducing the node's external network footprint. Unlike hostNetwork, hostPort still confines the container to its own network namespace, so it does not grant any additional host process or namespace access. It's a reasonable security consideration, but in the context of minimizing host access, it is not one of the three defining controls.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which of the following host access settings should be avoided to minimize the attack surface from containers? (Select the setting that increases risk the most.)
medium- ✓ A.hostPID: true
- B.securityContext: capabilities: drop: ["ALL"]
- C.readOnlyRootFilesystem: true
- D.resources: limits: memory: "512Mi"
Why A: Setting `hostPID: true` allows a container to share the host's process ID namespace, enabling it to see all processes running on the host. This breaks the fundamental isolation that containers should provide, giving a compromised container direct visibility into host processes and the ability to potentially interact with them (e.g., sending signals). This significantly increases the attack surface and is the most dangerous setting among the options.
Variation 2. Which of the following host access settings should be disabled to reduce the attack surface of a container?
easy- A.hostNetwork: true
- B.hostPID: true
- C.hostIPC: true
- ✓ D.hostPID: false
Why D: Setting `hostPID: false` explicitly disables the container's access to the host's process ID namespace, which reduces the attack surface by preventing the container from seeing or interacting with host processes. In Kubernetes, when `hostPID` is set to `true`, the container shares the host's PID namespace, allowing it to potentially escalate privileges or interfere with other workloads. Disabling this setting (i.e., `false`) is a recommended security best practice to enforce process isolation.
Variation 3. An administrator wants to prevent a container from accessing the host's network. Which pod security context field should be set to false?
easy- A.hostIPC
- B.privileged
- C.hostPID
- ✓ D.hostNetwork
Why D: The `hostNetwork` field in the Pod Security Context, when set to `true`, allows the container to use the host's network namespace directly, bypassing the pod's own network stack. Setting it to `false` (the default) ensures the container uses an isolated network namespace, preventing direct access to host network interfaces, iptables rules, and network services. This is the correct field to disable to meet the requirement of preventing container access to the host's network.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.