CS0-003 Vulnerability Management Practice Question
A security analyst is reviewing a vulnerability scan of a Kubernetes cluster. The scan reports that a container is running with privileged mode enabled. Which CIS Kubernetes Benchmark recommendation does this violation relate to?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure that containers are not running with privileged access
The CIS Kubernetes Benchmark includes a recommendation to avoid running containers with privileged access, as it increases security risks. This is a common misconfiguration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ensure that containers are not running with privileged access
Why this is correct
Running containers with privileged access essentially grants them the same capabilities as the host root user, bypassing container isolation boundaries. CIS Kubernetes benchmarks strongly recommend disabling privileged containers to prevent container breakout attacks, where an attacker compromises a container and escalates privileges to compromise the underlying node.
- ✗
Ensure that the cluster-admin role is not used
Why it's wrong here
While restricting the use of the cluster-admin role is a critical Kubernetes Role-Based Access Control (RBAC) best practice, it does not directly address container-level runtime privileges. This recommendation focuses on limiting administrative user and service account permissions within the control plane rather than preventing container breakout vulnerabilities on worker nodes.
- ✗
Ensure that the API server is not exposed to the internet
Why it's wrong here
Restricting public access to the Kubernetes API server is a vital network security control designed to reduce the cluster's external attack surface. However, this network-level mitigation does not prevent local privilege escalation or container escape risks associated with misconfigured workloads running inside the cluster.
- ✗
Ensure that etcd is configured with TLS
Why it's wrong here
Configuring Transport Layer Security (TLS) for the etcd datastore ensures the confidentiality and integrity of cluster state data in transit and at rest. While essential for securing the control plane's database, it does not mitigate the runtime risks of containers running with elevated host-level privileges.
Go deeper
Related to this question
Learn chapter
Penetration Testing vs Vulnerability Assessment
Key term
Privileged access
Privileged access is a special level of permission that allows a user or system to perform high-impact actions like installing software, changing system settings, or accessing sensitive data across an IT environment.
Key term
Vulnerability scan
A vulnerability scan is an automated process that checks systems, networks, and applications for known security weaknesses or misconfigurations.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.