Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is reviewing a Kubernetes cluster configuration. Which of the following misconfigurations poses the MOST severe security risk?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Privileged containers with unrestricted host access

Privileged containers bypass all security restrictions and can access the host system, posing the most severe risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Using hostPath mounts with read-only access

    Why it's wrong here

    A read-only hostPath mount lets a pod see host filesystem data but blocks it from writing or modifying that content, which meaningfully limits an attacker's ability to plant malicious files, tamper with host binaries, or achieve persistence, keeping the risk lower than a fully unrestricted host escape vector.

  • ✗

    Using ConfigMaps for non-sensitive data

    Why it's wrong here

    ConfigMaps are explicitly designed to hold non-confidential configuration data such as environment variables or config files in plaintext, so storing non-sensitive values there follows Kubernetes best practice rather than representing any kind of misconfiguration or security exposure.

  • ✓

    Privileged containers with unrestricted host access

    Why this is correct

    A privileged container runs with nearly all Linux capabilities enabled and direct access to host devices, meaning a compromised container can mount the host filesystem, load kernel modules, and effectively break out of container isolation entirely, giving an attacker root-equivalent control over the underlying node.

  • ✗

    Running containers as non-root user

    Why it's wrong here

    Enforcing non-root execution inside containers is a core Kubernetes and CIS Benchmark hardening recommendation because it limits the impact of a container-breakout or kernel-level exploit by denying the process root privileges within its own namespace, making this a protective setting rather than a vulnerability.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.