Courseiva
Vulnerability Management →hardMultiple Choice

CS0-003 Vulnerability Management Practice Question

During a vulnerability assessment of a Kubernetes cluster, a security analyst finds that a container is running with privileged mode enabled and has a hostPath mount that grants write access to the host's /var/log directory. Which of the following is the most significant security risk associated with this configuration?

⚠ Common exam trap

CS0-004 often tests container security risks. Candidates might focus on data leakage or network permissions, but the combination of privileged mode and hostPath write access is a classic container escape vector leading to host compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Potential for container escape and host node compromise

A container running in privileged mode with a hostPath mount that grants write access to the host's /var/log directory poses a significant risk of container escape and host node compromise. Privileged mode gives the container almost all capabilities of the host, and the hostPath mount allows direct write access to host files, enabling an attacker to modify system logs, plant malware, or escalate privileges to the host.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data leakage through unrestricted storage access

    Why it's wrong here

    Although mounting a hostPath volume can expose sensitive host files to the container and lead to unauthorized data access, this is a secondary consequence of the misconfiguration. The primary and most severe risk identified during a vulnerability assessment of privileged containers with host mounts is the total compromise of the underlying node, rather than isolated data leakage.

  • ✗

    Excessive network permissions allowing lateral movement

    Why it's wrong here

    Excessive network permissions and loose NetworkPolicies can indeed facilitate lateral movement across a Kubernetes cluster. However, this risk is associated with network-level configurations and service mesh policies, whereas the combination of privileged mode and hostPath mounts specifically introduces host-level virtualization escape risks rather than network-layer traversal.

  • ✓

    Potential for container escape and host node compromise

    Why this is correct

    Running a container in privileged mode eliminates the isolation boundaries enforced by namespaces and cgroups, granting the container near-root access to the host. When combined with a hostPath mount, an attacker can easily access the host's filesystem, manipulate system binaries, interact with the host's container runtime socket, and achieve full container escape to compromise the underlying node.

  • ✗

    Increased attack surface due to unnecessary services running in the container

    Why it's wrong here

    Including unnecessary services or packages within a container image expands its local attack surface and increases the number of exploitable software vulnerabilities. While minimizing image footprints is a security best practice, it does not address the immediate, critical architectural risk of host takeover posed by running a container with elevated privileges and direct host filesystem access.

Go deeper

Related to this question

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.