Courseiva
hardMultiple Select

CS0-003 Practice Question: A Kubernetes audit alert shows a service account…

A Kubernetes audit alert shows a service account creating privileged pods. Which checks are most relevant? (Choose two.)

⚠ Common exam trap

The CS0-004 exam often tests the ability to distinguish between operational metrics (like code comments or HR data) and security-relevant configuration fields, trapping candidates who confuse general IT audit items with Kubernetes-specific security indicators.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pod spec fields such as privileged mode, hostPath, and hostNetwork

Privileged pods can bypass container security boundaries, and hostPath or hostNetwork access can lead to host-level compromise. The audit alert specifically flags a service account creating such pods, which violates the principle of least privilege and indicates a potential security incident that requires immediate investigation of the pod spec fields.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The number of comments in application code

    Why it's wrong here

    Code comments reside within the application's source repository and do not impact the active runtime configuration of a Kubernetes cluster. Analyzing comment volume provides no insight into how a service account was compromised or what cluster-level resources it is attempting to manipulate. Security analysts should focus on active configuration manifests and audit logs rather than static source code documentation.

  • ✗

    User profile pictures in the HR system

    Why it's wrong here

    User profile pictures stored within an HR database are entirely decoupled from the Kubernetes control plane and its role-based access control (RBAC) framework. Investigating these assets does not yield any actionable intelligence regarding service account permissions, pod specifications, or container escape vectors. Analysts must prioritize cluster-native artifacts and configuration files to diagnose authorization anomalies.

  • ✓

    Pod spec fields such as privileged mode, hostPath, and hostNetwork

    Why this is correct

    Examining pod specification fields like 'privileged: true', 'hostPath', and 'hostNetwork' is critical because these parameters allow containers to bypass isolation boundaries. If a compromised service account deploys a pod with these configurations, it can access the underlying host node's filesystem, network namespace, and devices, potentially leading to a full cluster takeover. Security teams must scrutinize these fields to detect container escape attempts and privilege escalation.

  • ✓

    Recent role binding or cluster role binding changes

    Why this is correct

    Investigating recent modifications to RoleBindings and ClusterRoleBindings is essential to determine how the service account obtained the permissions necessary to perform unauthorized actions. Attackers often manipulate these RBAC resources to grant elevated cluster-admin privileges to a compromised service account. Correlating audit logs with binding changes helps trace the path of privilege escalation and identify the root cause of the malicious activity.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.