Courseiva
Vulnerability Management →mediumMultiple Select

CS0-003 Vulnerability Management Practice Question

A security analyst is conducting a vulnerability assessment of a Kubernetes cluster. Which TWO of the following are common misconfigurations that could lead to security risks? (Select TWO.)

⚠ Common exam trap

CS0-004 often tests the inversion of security best practices, so candidates must recognize that resource limits, network policies, and read-only filesystems are protections, while privileged mode and hostPath mounts are risks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Running containers in privileged mode

Option C is correct because running containers in privileged mode disables the container's isolation from the host, granting access to all Linux capabilities and devices (equivalent to --privileged), which allows a compromised container to escape and control the node. Option E is correct because hostPath mounts expose a file or directory from the node's filesystem directly into the pod, so a container can read or modify sensitive host paths such as /etc, /var/run/docker.sock, or /proc, enabling privilege escalation and node compromise. Options A and D are not misconfigurations but hardening measures: resource limits mitigate denial-of-service and noisy-neighbor risks, and read-only root filesystems prevent runtime tampering with container binaries. Option B is also a security control, not a risk, since Kubernetes NetworkPolicies restrict pod-to-pod traffic and enforce segmentation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Setting resource limits on containers

    Why it's wrong here

    Setting resource limits on containers constrains CPU, memory, and I/O usage, ensuring that a single compromised or misbehaving container cannot starve the host or neighboring containers of resources. This is a proactive hardening measure that mitigates denial-of-service and resource-exhaustion attacks. Far from being a vulnerability, it is a required security control in multi-tenant container environments.

  • ✗

    Configuring network policies to restrict traffic

    Why it's wrong here

    Configuring network policies to restrict traffic enforces a least-privilege model by defining which containers or pods can communicate with each other and with external endpoints. Without such policies, all inter-container traffic is typically allowed, expanding the blast radius of a compromise. Because this reduces the attack surface and limits lateral movement, it is a security best practice, not a risk.

  • ✓

    Running containers in privileged mode

    Why this is correct

    Running containers in privileged mode grants them every Linux capability, disables seccomp and AppArmor/SELinux confinement, and exposes all host devices, effectively removing isolation between the container and the host kernel. An attacker who exploits a vulnerability in a privileged container can trivially escalate to full host control, making it one of the most dangerous container misconfigurations. During a vulnerability assessment, this should immediately be flagged as a critical finding.

  • ✗

    Using read-only root filesystems

    Why it's wrong here

    Using read-only root filesystems prevents any process inside the container from writing to the container image's root filesystem layer, which stops attackers from dropping malware or modifying critical executables and configuration files. It forces any required writes to be done through explicit ephemeral volumes, maintaining filesystem integrity. This is a well-known defensive hardening technique that reduces the impact of a compromised container, so it is not a vulnerability.

  • ✓

    Using hostPath mounts

    Why this is correct

    Using hostPath mounts allows a container to directly access a directory on the host's filesystem, bypassing the container's filesystem isolation. If the mounted path is broad or sensitive (e.g., /, /etc, or /var/run/docker.sock), a compromised container can read or tamper with host files, leading to host takeover. This is a high-risk configuration that should be carefully audited and scoped to read-only, least-privilege paths during vulnerability assessment.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.