A company is deploying a cloud-native application that uses containers orchestrated by Kubernetes. The security team wants to enforce the principle of least privilege at the Kubernetes level. Which THREE measures should be implemented? (Choose three.)
Pod Security Standards enforce security contexts that limit pod capabilities.
Why this answer
Pod Security Standards (PSS) define security contexts for pods, with the 'restricted' policy enforcing the principle of least privilege by disallowing privileged containers, host network access, and other high-risk capabilities. This directly prevents pods from running with unnecessary permissions, aligning with the security team's goal at the pod level.
Exam trap
The CV0-004 exam often tests the distinction between network-level controls (network policies) and identity/privilege controls (RBAC, Pod Security Standards), leading candidates to mistakenly select network policies as a least-privilege measure when they only restrict traffic, not permissions.