GSEC Container Security Practice Question
An enterprise development team is designing a Kubernetes cluster deployment where application containers frequently interact with cloud provider APIs. To minimize security blast radius, which architectural practice provides the most effective credential isolation per pod?
⚠ Common exam trap
Candidates often suggest static secrets or Kubernetes Secrets objects, failing to realize that these are long-lived and pose a higher risk compared to short-lived, projected tokens.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement service account token volume projection with short-lived auditable tokens scoped to individual application requirements.
Service account token volume projection utilizes short-lived tokens cryptographically signed by the cluster, mounting them securely into specific pods with restricted audiences. This approach replaces static long-lived credentials stored in environment variables or generic secrets, significantly reducing lateral movement risks if an application is compromised.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store cloud provider credentials in base64-encoded Kubernetes Secret objects and mount them as environment variables.
Why it's wrong here
Base64 encoding is merely obfuscation, not encryption at rest. Environment variables are notoriously insecure because they can be easily dumped by malicious processes running inside the container or exposed via debugging interfaces and container inspection logs.
- ✗
Configure cluster-wide IAM roles on the underlying worker nodes and allow all hosted pods to inherit administrative permissions.
Why it's wrong here
Inheriting node-level administrative permissions violates the principle of least privilege. Any compromise of a single low-risk pod would immediately grant an attacker full administrative control over all cloud provider resources accessible by that worker node.
- ✓
Implement service account token volume projection with short-lived auditable tokens scoped to individual application requirements.
Why this is correct
Projected service account tokens provide automatically rotated, cryptographically signed tokens with strict audience limitations. This ensures that even if a token is exfiltrated, its lifespan is extremely short and its usability is strictly bounded to intended APIs.
- ✗
Embed the static cloud API keys directly into the container base image layers to ensure consistency across deployments.
Why it's wrong here
Embedding credentials inside container image layers makes them permanently accessible to anyone who pulls the image from the registry. Image layers persist sensitive data indefinitely even if the files are subsequently deleted in later build stages.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.