Courseiva
Cluster Hardening →easyMultiple Select

CKS Cluster Hardening Practice Question

Which TWO of the following are best practices for securing container images?

⚠ Common exam trap

CNCF often tests the misconception that using the 'latest' tag is safe or recommended, when in fact it is a security anti-pattern that undermines image integrity and reproducibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use minimal base images like distroless

Minimal base images like distroless reduce the attack surface by eliminating unnecessary packages, libraries, and shell access. This aligns with the principle of least functionality, making it harder for attackers to exploit vulnerabilities or execute arbitrary commands within the container. Distroless images typically contain only the application and its runtime dependencies, significantly lowering the risk of privilege escalation or lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Always use the latest tag

    Why it's wrong here

    Using the `latest` tag means the same tag may refer to a different image digest tomorrow; a rebuild or an upstream push silently changes what your cluster runs. This breaks reproducibility, makes rollbacks harder, and can pull in newly introduced vulnerabilities or incompatible versions. For auditability and supply-chain security, always reference images by an exact digest (e.g., `image@sha256:...`) or at least a fully versioned and internally managed tag.

  • ✓

    Use minimal base images like distroless

    Why this is correct

    Distroless base images contain only the application and its runtime libraries, omitting shells, package managers, and compilers. This dramatically reduces the attack surface because an attacker who gains code execution has no interactive shell, no apt/yum, and no build toolchain to pivot with, and there are fewer packages to scan for known vulnerabilities. They also encourage running as non-root and keeping the filesystem read-only.

  • ✗

    Run containers as root

    Why it's wrong here

    Running as root (UID 0) inside a container is dangerous because kernel vulnerabilities or misconfigurations can allow a container process to perform actions with host root privileges. Even without an escape, root can modify binaries, install tools, or tamper with runtime metadata inside the container. The pod security context should set `runAsNonRoot: true` or a numeric non-zero UID, and the container image should declare a dedicated user.

  • ✗

    Run containers in privileged mode

    Why it's wrong here

    Privileged mode essentially disables the container runtime’s isolation: it grants all Linux capabilities, allows access to host devices, and typically disables restrictions like seccomp and AppArmor. A single vulnerability in a privileged container can give an attacker direct access to the host kernel, device files, and cgroups, effectively yielding host root. It should never be used unless absolutely required, and alternatives like specific capability drops or device annotations should be applied.

  • ✓

    Use image vulnerability scanning

    Why this is correct

    Image vulnerability scanning compares the content of image layers against public CVE databases (e.g., via Trivy, Grype, or Clair). Running these scans in CI/CD and on the registry identifies known operating-system and dependency vulnerabilities before they reach production, allowing teams to block critical findings or reject images older than a threshold. Scanning should be continuous, not one-time, because new CVEs are disclosed after the image is built.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.