CS0-003 Vulnerability Management Practice Question
A security analyst is conducting a vulnerability assessment of a Kubernetes cluster. Which TWO of the following are common misconfigurations that could lead to security risks? (Select TWO.)
⚠ Common exam trap
CS0-004 often tests the inversion of security best practices, so candidates must recognize that resource limits, network policies, and read-only filesystems are protections, while privileged mode and hostPath mounts are risks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Running containers in privileged mode
Option C is correct because running containers in privileged mode disables the container's isolation from the host, granting access to all Linux capabilities and devices (equivalent to --privileged), which allows a compromised container to escape and control the node. Option E is correct because hostPath mounts expose a file or directory from the node's filesystem directly into the pod, so a container can read or modify sensitive host paths such as /etc, /var/run/docker.sock, or /proc, enabling privilege escalation and node compromise. Options A and D are not misconfigurations but hardening measures: resource limits mitigate denial-of-service and noisy-neighbor risks, and read-only root filesystems prevent runtime tampering with container binaries. Option B is also a security control, not a risk, since Kubernetes NetworkPolicies restrict pod-to-pod traffic and enforce segmentation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Setting resource limits on containers
Why it's wrong here
Setting resource limits on containers constrains CPU, memory, and I/O usage, ensuring that a single compromised or misbehaving container cannot starve the host or neighboring containers of resources. This is a proactive hardening measure that mitigates denial-of-service and resource-exhaustion attacks. Far from being a vulnerability, it is a required security control in multi-tenant container environments.
- ✗
Configuring network policies to restrict traffic
Why it's wrong here
Configuring network policies to restrict traffic enforces a least-privilege model by defining which containers or pods can communicate with each other and with external endpoints. Without such policies, all inter-container traffic is typically allowed, expanding the blast radius of a compromise. Because this reduces the attack surface and limits lateral movement, it is a security best practice, not a risk.
- ✓
Running containers in privileged mode
Why this is correct
Running containers in privileged mode grants them every Linux capability, disables seccomp and AppArmor/SELinux confinement, and exposes all host devices, effectively removing isolation between the container and the host kernel. An attacker who exploits a vulnerability in a privileged container can trivially escalate to full host control, making it one of the most dangerous container misconfigurations. During a vulnerability assessment, this should immediately be flagged as a critical finding.
- ✗
Using read-only root filesystems
Why it's wrong here
Using read-only root filesystems prevents any process inside the container from writing to the container image's root filesystem layer, which stops attackers from dropping malware or modifying critical executables and configuration files. It forces any required writes to be done through explicit ephemeral volumes, maintaining filesystem integrity. This is a well-known defensive hardening technique that reduces the impact of a compromised container, so it is not a vulnerability.
- ✓
Using hostPath mounts
Why this is correct
Using hostPath mounts allows a container to directly access a directory on the host's filesystem, bypassing the container's filesystem isolation. If the mounted path is broad or sensitive (e.g., /, /etc, or /var/run/docker.sock), a compromised container can read or tamper with host files, leading to host takeover. This is a high-risk configuration that should be carefully audited and scoped to read-only, least-privilege paths during vulnerability assessment.
Go deeper
Related to this question
Learn chapter
Zeek for Network Traffic Analysis
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Security control
A security control is a safeguard or countermeasure designed to protect the confidentiality, integrity, and availability of information systems and data.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.