Courseiva
Vulnerability Management →hardMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is reviewing a vulnerability scan of a Kubernetes cluster. The scan reports that a container is running with privileged mode enabled. Which CIS Kubernetes Benchmark recommendation does this violation relate to?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure that containers are not running with privileged access

The CIS Kubernetes Benchmark includes a recommendation to avoid running containers with privileged access, as it increases security risks. This is a common misconfiguration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ensure that containers are not running with privileged access

    Why this is correct

    Running containers with privileged access essentially grants them the same capabilities as the host root user, bypassing container isolation boundaries. CIS Kubernetes benchmarks strongly recommend disabling privileged containers to prevent container breakout attacks, where an attacker compromises a container and escalates privileges to compromise the underlying node.

  • ✗

    Ensure that the cluster-admin role is not used

    Why it's wrong here

    While restricting the use of the cluster-admin role is a critical Kubernetes Role-Based Access Control (RBAC) best practice, it does not directly address container-level runtime privileges. This recommendation focuses on limiting administrative user and service account permissions within the control plane rather than preventing container breakout vulnerabilities on worker nodes.

  • ✗

    Ensure that the API server is not exposed to the internet

    Why it's wrong here

    Restricting public access to the Kubernetes API server is a vital network security control designed to reduce the cluster's external attack surface. However, this network-level mitigation does not prevent local privilege escalation or container escape risks associated with misconfigured workloads running inside the cluster.

  • ✗

    Ensure that etcd is configured with TLS

    Why it's wrong here

    Configuring Transport Layer Security (TLS) for the etcd datastore ensures the confidentiality and integrity of cluster state data in transit and at rest. While essential for securing the control plane's database, it does not mitigate the runtime risks of containers running with elevated host-level privileges.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.