Courseiva
Vulnerability Management →hardMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is investigating a Kubernetes cluster and finds that a container is running with securityContext.privileged: true. The container also has a hostPath mount that allows writing to the host filesystem. Which of the following best describes the primary risk of this configuration?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The container can break out of the container environment and gain root access to the host node.

A privileged container with hostPath mount can escape the container and compromise the host. The container can access host resources, potentially allowing full host compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The container can only read host files, but not modify them.

    Why it's wrong here

    A hostPath volume mount defaults to read-write access unless it is explicitly configured as read-only. When combined with privileged mode, the container process bypasses standard kernel namespace restrictions and can freely modify, delete, or create critical files directly on the host node's filesystem.

  • ✗

    The container can only affect other containers in the same pod, not the host.

    Why it's wrong here

    While pod-level isolation typically restricts container interaction, a hostPath mount breaks this boundary by mapping a directory from the host node directly into the container. This configuration allows the container to interact directly with the underlying host's operating system, rendering the pod-level containment boundary ineffective.

  • ✗

    The container can be used to launch a denial-of-service attack on the Kubernetes API server.

    Why it's wrong here

    Although a compromised container could theoretically flood the Kubernetes API server with requests, this is a secondary network-based threat rather than the primary architectural risk. The immediate, high-severity risk of this specific configuration is local privilege escalation and host takeover, not API-focused denial-of-service.

  • ✓

    The container can break out of the container environment and gain root access to the host node.

    Why this is correct

    Running a container in privileged mode grants it nearly all capabilities of the host's root user, disabling Linux namespaces and cgroups protections. When paired with a hostPath mount, an attacker can easily escape the container boundaries, access the host's sensitive system files, and execute arbitrary commands with root privileges on the underlying node.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.