GSEC Container Security Practice Question
A platform team runs a Kubernetes cluster where a container was compromised through a remote code execution flaw in a web application. The attacker attempted to read the service account token, query the API server, and list secrets in the namespace. The team wants to reduce the impact of such a compromise in the future. Which of the following changes most directly limits what the compromised pod's service account can do against the API server?
⚠ Common exam trap
The trap here is treating observability or network controls as equivalent to authorization, when only RBAC scope determines what a service account is permitted to do.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Binding a tightly scoped Role to the service account that grants only the specific verbs and resources the application requires, instead of cluster-admin or broad default permissions.
RBAC least privilege is the authoritative control over what a service account can do against the API server. Binding a narrowly scoped Role that grants only the required verbs and resources means a compromised pod's token cannot enumerate secrets or perform privileged actions, directly containing the blast radius from the RCE compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enabling audit logging on the API server to record all requests made by service accounts.
Why it's wrong here
Audit logging records what happens but does not restrict what a service account can do. The attacker would still be able to list secrets and query the API server; the logs would only document the activity after the fact. The team's goal is to limit the blast radius, which requires authorization controls, not observability.
- ✗
Disabling the automountServiceAccountToken field on the pod spec so no token is projected into the container.
Why it's wrong here
Disabling token automount prevents the pod from receiving a service account token, which does limit API access. However, the question asks what most directly limits what the service account can do when a token is present. Removing the token is a valid hardening step but does not address the authorization scope if a token is obtained by other means.
- ✗
Applying a NetworkPolicy that blocks egress from the pod to the API server's ClusterIP.
Why it's wrong here
Blocking egress to the API server would prevent the pod from reaching it, but many applications legitimately need API access for service discovery or controllers. It is a blunt control that can break functionality and does not address authorization if the token is used from another network path. The precise control for limiting what a service account can do is RBAC scoping, not network isolation.
- ✓
Binding a tightly scoped Role to the service account that grants only the specific verbs and resources the application requires, instead of cluster-admin or broad default permissions.
Why this is correct
RBAC bindings define exactly which API verbs and resources a service account may access. Replacing broad permissions with a least-privilege Role ensures that even if the container is compromised, the token cannot list secrets or perform privileged operations. This directly limits the blast radius against the API server, matching the team's objective.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.