CKS Cluster Hardening Practice Question
Which TWO of the following are best practices for securing container images?
⚠ Common exam trap
CNCF often tests the misconception that using the 'latest' tag is safe or recommended, when in fact it is a security anti-pattern that undermines image integrity and reproducibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use minimal base images like distroless
Minimal base images like distroless reduce the attack surface by eliminating unnecessary packages, libraries, and shell access. This aligns with the principle of least functionality, making it harder for attackers to exploit vulnerabilities or execute arbitrary commands within the container. Distroless images typically contain only the application and its runtime dependencies, significantly lowering the risk of privilege escalation or lateral movement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Always use the latest tag
Why it's wrong here
Using the `latest` tag means the same tag may refer to a different image digest tomorrow; a rebuild or an upstream push silently changes what your cluster runs. This breaks reproducibility, makes rollbacks harder, and can pull in newly introduced vulnerabilities or incompatible versions. For auditability and supply-chain security, always reference images by an exact digest (e.g., `image@sha256:...`) or at least a fully versioned and internally managed tag.
- ✓
Use minimal base images like distroless
Why this is correct
Distroless base images contain only the application and its runtime libraries, omitting shells, package managers, and compilers. This dramatically reduces the attack surface because an attacker who gains code execution has no interactive shell, no apt/yum, and no build toolchain to pivot with, and there are fewer packages to scan for known vulnerabilities. They also encourage running as non-root and keeping the filesystem read-only.
- ✗
Run containers as root
Why it's wrong here
Running as root (UID 0) inside a container is dangerous because kernel vulnerabilities or misconfigurations can allow a container process to perform actions with host root privileges. Even without an escape, root can modify binaries, install tools, or tamper with runtime metadata inside the container. The pod security context should set `runAsNonRoot: true` or a numeric non-zero UID, and the container image should declare a dedicated user.
- ✗
Run containers in privileged mode
Why it's wrong here
Privileged mode essentially disables the container runtime’s isolation: it grants all Linux capabilities, allows access to host devices, and typically disables restrictions like seccomp and AppArmor. A single vulnerability in a privileged container can give an attacker direct access to the host kernel, device files, and cgroups, effectively yielding host root. It should never be used unless absolutely required, and alternatives like specific capability drops or device annotations should be applied.
- ✓
Use image vulnerability scanning
Why this is correct
Image vulnerability scanning compares the content of image layers against public CVE databases (e.g., via Trivy, Grype, or Clair). Running these scans in CI/CD and on the registry identifies known operating-system and dependency vulnerabilities before they reach production, allowing teams to block critical findings or reject images older than a threshold. Scanning should be continuous, not one-time, because new CVEs are disclosed after the image is built.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.