Courseiva
Container Security →mediumMultiple Choice

GSEC Container Security Practice Question

An enterprise development team is designing a Kubernetes cluster deployment where application containers frequently interact with cloud provider APIs. To minimize security blast radius, which architectural practice provides the most effective credential isolation per pod?

⚠ Common exam trap

Candidates often suggest static secrets or Kubernetes Secrets objects, failing to realize that these are long-lived and pose a higher risk compared to short-lived, projected tokens.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement service account token volume projection with short-lived auditable tokens scoped to individual application requirements.

Service account token volume projection utilizes short-lived tokens cryptographically signed by the cluster, mounting them securely into specific pods with restricted audiences. This approach replaces static long-lived credentials stored in environment variables or generic secrets, significantly reducing lateral movement risks if an application is compromised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store cloud provider credentials in base64-encoded Kubernetes Secret objects and mount them as environment variables.

    Why it's wrong here

    Base64 encoding is merely obfuscation, not encryption at rest. Environment variables are notoriously insecure because they can be easily dumped by malicious processes running inside the container or exposed via debugging interfaces and container inspection logs.

  • ✗

    Configure cluster-wide IAM roles on the underlying worker nodes and allow all hosted pods to inherit administrative permissions.

    Why it's wrong here

    Inheriting node-level administrative permissions violates the principle of least privilege. Any compromise of a single low-risk pod would immediately grant an attacker full administrative control over all cloud provider resources accessible by that worker node.

  • ✓

    Implement service account token volume projection with short-lived auditable tokens scoped to individual application requirements.

    Why this is correct

    Projected service account tokens provide automatically rotated, cryptographically signed tokens with strict audience limitations. This ensures that even if a token is exfiltrated, its lifespan is extremely short and its usability is strictly bounded to intended APIs.

  • ✗

    Embed the static cloud API keys directly into the container base image layers to ensure consistency across deployments.

    Why it's wrong here

    Embedding credentials inside container image layers makes them permanently accessible to anyone who pulls the image from the registry. Image layers persist sensitive data indefinitely even if the files are subsequently deleted in later build stages.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.