GSEC Virtualization, Cloud, and AI Essentials Practice Question
A startup is deploying a containerized web application on a managed Kubernetes service. The security lead wants to ensure that if a container is compromised, the attacker cannot easily move laterally to other workloads or the underlying node. Which Kubernetes feature most directly restricts a compromised container's ability to reach other pods and node services?
⚠ Common exam trap
Many candidates confuse admission-time controls like PodSecurityPolicy with runtime network segmentation, when only NetworkPolicy governs pod-to-pod traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NetworkPolicy resources that define allowed ingress and egress traffic for selected pods.
By default, Kubernetes allows all pods to communicate with each other and with node services. NetworkPolicy provides a declarative way to restrict ingress and egress at the pod level, effectively segmenting workloads so a compromised container cannot reach unrelated services or the node. Admission controls and resource quotas address different concerns and do not constrain network paths.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
NetworkPolicy resources that define allowed ingress and egress traffic for selected pods.
Why this is correct
NetworkPolicy acts as a pod-level firewall, allowing administrators to specify which pods, namespaces, and ports can communicate. By default, pods can reach each other freely, so a compromised container can scan and attack neighbors. Applying restrictive ingress and egress policies limits lateral movement and blocks access to node services, directly containing a breach.
- ✗
ResourceQuota objects that limit CPU and memory consumption per namespace.
Why it's wrong here
ResourceQuota prevents resource exhaustion and noisy-neighbor problems by capping compute and storage usage. It has no bearing on network reachability, so a compromised container can still communicate with other pods and node services. This control addresses availability and capacity planning, not lateral movement, and therefore does not satisfy the security lead's requirement.
- ✗
Horizontal Pod Autoscaler configured to scale replicas based on CPU utilization.
Why it's wrong here
The Horizontal Pod Autoscaler adjusts the number of pod replicas in response to load. It is an availability and performance mechanism and does not filter or restrict network traffic. Scaling up replicas could even increase the attack surface if those pods are equally reachable, so it does not limit lateral movement from a compromised container.
- ✗
PodSecurityPolicy admission controller configured to disallow privileged containers.
Why it's wrong here
PodSecurityPolicy governs pod creation requirements such as privilege, volume types, and capabilities. It does not control network traffic between running pods, so a compromised container could still reach other workloads over the network. It reduces the impact of a container escape but does not restrict lateral movement at the network layer, making it the wrong control for this objective.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.