hardMultiple Select
CS0-003 Practice Question: A Kubernetes audit alert shows a service account…
A Kubernetes audit alert shows a service account creating privileged pods. Which checks are most relevant? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests the ability to distinguish between operational metrics (like code comments or HR data) and security-relevant configuration fields, trapping candidates who confuse general IT audit items with Kubernetes-specific security indicators.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pod spec fields such as privileged mode, hostPath, and hostNetwork
Privileged pods can bypass container security boundaries, and hostPath or hostNetwork access can lead to host-level compromise. The audit alert specifically flags a service account creating such pods, which violates the principle of least privilege and indicates a potential security incident that requires immediate investigation of the pod spec fields.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The number of comments in application code
Why it's wrong here
Code comments reside within the application's source repository and do not impact the active runtime configuration of a Kubernetes cluster. Analyzing comment volume provides no insight into how a service account was compromised or what cluster-level resources it is attempting to manipulate. Security analysts should focus on active configuration manifests and audit logs rather than static source code documentation.
- ✗
User profile pictures in the HR system
Why it's wrong here
User profile pictures stored within an HR database are entirely decoupled from the Kubernetes control plane and its role-based access control (RBAC) framework. Investigating these assets does not yield any actionable intelligence regarding service account permissions, pod specifications, or container escape vectors. Analysts must prioritize cluster-native artifacts and configuration files to diagnose authorization anomalies.
- ✓
Pod spec fields such as privileged mode, hostPath, and hostNetwork
Why this is correct
Examining pod specification fields like 'privileged: true', 'hostPath', and 'hostNetwork' is critical because these parameters allow containers to bypass isolation boundaries. If a compromised service account deploys a pod with these configurations, it can access the underlying host node's filesystem, network namespace, and devices, potentially leading to a full cluster takeover. Security teams must scrutinize these fields to detect container escape attempts and privilege escalation.
- ✓
Recent role binding or cluster role binding changes
Why this is correct
Investigating recent modifications to RoleBindings and ClusterRoleBindings is essential to determine how the service account obtained the permissions necessary to perform unauthorized actions. Attackers often manipulate these RBAC resources to grant elevated cluster-admin privileges to a compromised service account. Correlating audit logs with binding changes helps trace the path of privilege escalation and identify the root cause of the malicious activity.
Go deeper
Related to this question
Learn chapter
Infrastructure-as-Code Security Scanning
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.