Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

Which THREE of the following are capabilities that should typically be dropped from a container to minimize vulnerabilities?

⚠ Common exam trap

Candidates often mistakenly believe that only network-related capabilities (NET_ADMIN, NET_RAW) should be dropped, but SETUID is also commonly dropped to prevent privilege escalation. Conversely, CHOWN and KILL are typically kept as they are less risky for container isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NET_ADMIN

NET_ADMIN (B) is a powerful Linux capability that allows a container to perform network administration tasks such as modifying routing tables, firewall rules (iptables/nftables), and network interface configurations. Dropping this capability prevents a compromised container from altering the host's network stack or bypassing network policies, which is critical for minimizing the attack surface in a microservice environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CHOWN

    Why it's wrong here

    CHOWN allows a process to change the ownership of files and directories, which is essential for many containerized applications that need to modify permissions on mounted volumes or prepare data for other processes. Dropping CAP_CHOWN would break common operational patterns, such as a non-root application chowning a file to its own user ID, and provides little security benefit because an attacker already running code in the container can often write to files directly. Therefore, it is a capability that is typically retained rather than dropped.

  • ✓

    NET_ADMIN

    Why this is correct

    CAP_NET_ADMIN grants comprehensive control over the network stack, including the ability to configure network interfaces, manage routing tables, set firewall rules, and manipulate packet filters. This capability is extremely powerful because an attacker can use it to redirect traffic, disable security monitoring, or create rogue network paths, effectively compromising network isolation. Since most containerized workloads do not require low-level network administration, this capability is often dropped as a hardening measure in cluster security policies.

  • ✓

    NET_RAW

    Why this is correct

    CAP_NET_RAW permits a process to create raw sockets, allowing it to craft and send arbitrary IP packets, sniff network traffic, and spoof source addresses. Attackers can leverage this to perform reconnaissance, launch man-in-the-middle attacks, or inject malicious packets into the network. Because raw socket access is rarely needed for normal application functionality and the risk of abuse is high, dropping CAP_NET_RAW is a standard practice in secure container runtimes.

  • ✗

    KILL

    Why it's wrong here

    CAP_KILL enables a process to send signals to any other process, bypassing normal permission checks. However, this capability is not traditionally dropped because signals are a fundamental mechanism for process management, and many container runners rely on sending SIGTERM or SIGKILL for graceful shutdown and cleanup. While an attacker could use CAP_KILL to terminate other containers, the impact is limited to denial-of-service and does not directly lead to privilege escalation, so the potential breakage of dropping it outweighs the security benefit.

  • ✓

    SETUID

    Why this is correct

    CAP_SETUID allows a process to change its effective user ID and to execute setuid binaries, which run with the permissions of the file owner. This is a direct route to privilege escalation: a compromised container process could invoke a setuid root binary to gain root privileges on the host if not properly isolated. Removing CAP_SETUID ensures that the process cannot elevate its privileges regardless of its actions, making it a critical capability to drop in a hardened container environment.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.