GSEC Container Security Practice Question
A GSEC candidate is reviewing a Docker Compose file for a web application. The file includes a service definition that mounts the Docker socket into the container. What is the primary security risk of this configuration?
⚠ Common exam trap
The trap here is assuming that mounting the Docker socket only affects container networking or filesystem isolation, when in fact it grants control over the host's Docker daemon and can lead to full host compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It allows the container to access the host's Docker daemon, enabling privilege escalation and full host compromise.
Mounting the Docker socket into a container effectively gives that container root-level control over the host's Docker daemon. An attacker who compromises the container can use the Docker API to start privileged containers, mount host directories, or execute commands on the host, resulting in full system compromise. This is a critical misconfiguration that should be avoided.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It prevents the container from writing to its own filesystem, causing application failures.
Why it's wrong here
Mounting the Docker socket does not affect the container's ability to write to its own filesystem. It provides access to the Docker daemon, which is a security risk, not a filesystem write restriction. Application failures would be due to other misconfigurations.
- ✓
It allows the container to access the host's Docker daemon, enabling privilege escalation and full host compromise.
Why this is correct
Mounting the Docker socket (/var/run/docker.sock) into a container grants that container control over the Docker daemon, which typically runs as root. An attacker could use the Docker API to create privileged containers, mount host filesystems, or escape to the host, leading to full compromise.
- ✗
It exposes the container's internal ports to the host network, increasing the attack surface.
Why it's wrong here
Mounting the Docker socket does not directly expose container ports; port exposure is controlled by the -p or --publish flags or the ports section in Compose. While port exposure can increase attack surface, it is not the primary risk of mounting the Docker socket.
- ✗
It allows the container to bypass network policies and communicate with other containers without restriction.
Why it's wrong here
While Docker socket access could be used to manipulate network settings, bypassing network policies is not the direct or primary risk. The immediate danger is the ability to control the Docker daemon, which can lead to host compromise. Network policies are typically enforced at the orchestration layer.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.