Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

Which THREE of the following are valid capabilities that should be dropped for a container running a typical non-privileged application to adhere to the principle of least privilege?

⚠ Common exam trap

A common misconception is that CHOWN or SETUID are high-risk capabilities that must be dropped, when in fact they are commonly needed for legitimate application behavior. The capabilities typically dropped for non-privileged containers are SYS_ADMIN, NET_RAW, and NET_ADMIN.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SYS_ADMIN

The SYS_ADMIN capability is a highly privileged capability that grants access to a wide range of system administration operations, such as mounting filesystems, namespace manipulation, and kernel settings. For a typical non-privileged application, dropping SYS_ADMIN is essential to adhere to the principle of least privilege, as it prevents the container from performing host-level administrative actions that could compromise isolation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CHOWN

    Why it's wrong here

    The CHOWN capability grants a process the right to change the owner and group of arbitrary files. While it does allow a container to alter file metadata, this is often required for legitimate application behavior, such as when an app running as a non-root user needs to correct ownership after mounting a volume. Dropping CHOWN indiscriminately can break standard operations like package installation or user permission adjustments, and it does not grant anywhere near the broad host-level control of SYS_ADMIN or NET_ADMIN. Therefore, CHOWN is not among the 'big three' capabilities that should be dropped as a default security hardening step.

  • ✓

    SYS_ADMIN

    Why this is correct

    SYS_ADMIN is the most dangerous capability a container can possess because it is effectively a near-root superpower that bypasses namespace isolation. It permits a process to perform privileged system calls such as mount(), pivot_root(), setns(), and unshare(), which can directly modify the host kernel and filesystem if exploited. For example, an attacker with SYS_ADMIN could mount the host's filesystem into the container or move a process into the host's PID namespace. Since virtually no containerized application legitimately needs these operations, SYS_ADMIN should always be dropped from a pod's security context (and from the default Docker seccomp profile, where it is disabled by default).

  • ✓

    NET_RAW

    Why this is correct

    NET_RAW allows a process to create raw sockets, which is necessary for low-level network utilities like ping (ICMP) but also enables packet crafting and spoofing. With raw sockets, an attacker inside a container could forge arbitrary IP packets, send spoofed ARP messages, or replace the contents of network requests to launch man-in-the-middle or denial-of-service attacks. Typical web application processes only require TCP/UDP sockets via the network stack and never need to manipulate packet headers directly. Consequently, NET_RAW is one of the capabilities recommended to drop in Kubernetes security contexts, and it is also removed in Docker's default seccomp profile, which strips it from all containers by default.

  • ✗

    SETUID

    Why it's wrong here

    SETUID enables a process to change its effective user and group IDs after startup, which is a standard mechanism for programs like sudo, passwd, and mount to temporarily elevate privileges. Many Linux distributions and container images include setuid binaries as part of their base system, and dropping SETUID globally can cause these binaries to malfunction or prevent legitimate privilege transitions. Unlike SYS_ADMIN or NET_ADMIN, SETUID does not grant arbitrary host control; it only allows ID switching within the allowed set of capabilities, and the risk is often mitigated by careful user namespace configuration. Thus, while it is not trivially safe to keep, it is not one of the three capabilities that are almost universally recommended for removal in the same category as the network and namespace ones.

  • ✓

    NET_ADMIN

    Why this is correct

    NET_ADMIN gives a process comprehensive control over the networking stack, including the ability to modify interface configuration, routing tables, IP tables (iptables), firewall rules, and packet classification. This is far more than an application needs to make ordinary network connections; a typical web server only needs to bind to a port and establish sockets. If an attacker gains NET_ADMIN, they can redirect traffic, drop packets, rewrite firewall rules, or turn the container into a network pivot point. For this reason, NET_ADMIN is considered a high-risk capability in security benchmarks (e.g., CIS Docker) and is explicitly recommended to be dropped from container runtimes and Kubernetes security contexts.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.