A security analyst is evaluating a Kubernetes cluster for misconfigurations. Which TWO of the following are common Kubernetes misconfigurations that increase security risk? (Select the two best answers.)
Trap 1: Running containers as non-root user
Running as non-root is a hardening measure, not a misconfiguration; it reduces risk by limiting container privilege. It is tempting because root containers are genuinely dangerous, so the phrasing inverts the question. The stem asks for settings that increase risk, such as privileged mode or hostPath mounts.
Trap 2: Enabling Role-Based Access Control (RBAC)
RBAC restricts cluster access by binding roles to users and service accounts, so enabling it lowers risk rather than creating a misconfiguration. It is tempting because a permissive RBAC configuration is dangerous, but the option describes enabling the mechanism itself, not misconfiguring it.
Trap 3: Implementing network policies to restrict traffic
Network policies restrict pod traffic and are a recommended hardening control, so implementing them reduces risk rather than creating a misconfiguration. It is tempting because policies can be misconfigured, but the question asks for common misconfigurations, and this option describes the correct secure practice.
- A
Running containers as non-root user
Why it fails: Running as non-root is a hardening measure, not a misconfiguration; it reduces risk by limiting container privilege. It is tempting because root containers are genuinely dangerous, so the phrasing inverts the question. The stem asks for settings that increase risk, such as privileged mode or hostPath mounts.
- B
Using hostPath mounts
hostPath mounts bind a node's filesystem directory into a pod, breaking container isolation. A compromised pod can then read or write node files, including credentials and the kubelet configuration, escalating beyond its namespace and undermining the cluster's security boundary.
- C
Using privileged containers
Privileged containers run with all Linux capabilities and direct host device access, effectively disabling container isolation. A breakout grants root on the node, so this misconfiguration sharply increases risk across the cluster's workloads and underlying infrastructure.
- D
Enabling Role-Based Access Control (RBAC)
Why it fails: RBAC restricts cluster access by binding roles to users and service accounts, so enabling it lowers risk rather than creating a misconfiguration. It is tempting because a permissive RBAC configuration is dangerous, but the option describes enabling the mechanism itself, not misconfiguring it.
- E
Implementing network policies to restrict traffic
Why it fails: Network policies restrict pod traffic and are a recommended hardening control, so implementing them reduces risk rather than creating a misconfiguration. It is tempting because policies can be misconfigured, but the question asks for common misconfigurations, and this option describes the correct secure practice.