GSEC · domain
Container Security
This domain covers securing containerized workloads and orchestrators on Linux hosts. GSEC questions present Dockerfiles, Kubernetes manifests, and multi-tenant cluster scenarios, then ask you to pick the control that best limits blast radius, protects the host kernel, or prevents credential exposure in images and running pods.
Focused practice
Practice Container Security questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Container Security
Be able to read a Dockerfile or Kubernetes manifest and choose the control that actually reduces host-kernel or credential exposure. The single most important thing: understand that image layers and default cluster permissions persist, so secrets and privilege must be removed at build time and enforced at runtime.
Applying Kubernetes Pod Security Standards, seccomp, AppArmor, and read-only root filesystems to limit container privilege
Using Dockerfile multi-stage builds, .dockerignore, and non-root USER to keep secrets and build artifacts out of images
Configuring Kubernetes RBAC, NetworkPolicy, and service accounts to isolate multi-tenant namespaces and restrict kubelet access
Hardening the container runtime with user namespaces, dropped Linux capabilities, and rootless or gVisor sandboxing
Watch out for
Common Container Security exam traps
- ▸Believing deleting a secret in a later Dockerfile layer removes it; earlier layers still contain the credential and remain pullable.
- ▸Assuming namespace separation alone isolates tenants, while default service accounts, hostPath mounts, or missing NetworkPolicy still allow lateral access.
- ▸Confusing image scanning with runtime protection; a clean scan does not stop a compromised container from abusing host kernel interfaces.
Question index
All Container Security questions (13)
Click any question to see the full explanation, or start a practice session above.
A GSEC analyst is reviewing the deployment pipeline for a containerized Node.js service. The Dockerfile contains a layer that runs `curl -fsSL https://example.com/install.sh | sh` during the build, before the image is pushed to an internal registry. The registry enforces vulnerability scanning, and the image is deployed to a Kubernetes cluster with a restrictive NetworkPolicy. Which of the following is the primary supply chain risk introduced by this Dockerfile instruction?
Hard2A GSEC candidate is reviewing a Docker Compose file for a web application. The file includes a service definition that mounts the Docker socket into the container. What is the primary security risk of this configuration?
Medium3A platform team runs a Kubernetes cluster where a container was compromised through a remote code execution flaw in a web application. The attacker attempted to read the service account token, query the API server, and list secrets in the namespace. The team wants to reduce the impact of such a compromise in the future. Which of the following changes most directly limits what the compromised pod's service account can do against the API server?
Hard4A security analyst is examining a Kubernetes Pod specification that includes the following securityContext: runAsUser: 0. What is the security implication of this setting?
Easy5A security engineer wants to ensure that container images are not modified after they are built and pushed to a registry. Which mechanism provides the strongest assurance of image integrity and authenticity?
Medium6A security engineer is evaluating a container runtime for a production Kubernetes cluster. The requirement is that the runtime must not share the host kernel with containers, providing stronger isolation than standard runc-based containers. Which of the following runtimes best satisfies this requirement?
Medium7Refer to the exhibit. What is the security impact of the provided Kubernetes security context configuration?
Medium8When designing a secure container orchestration strategy, which approach best minimizes the impact of a compromised container on the host kernel?
Medium9A security engineer is hardening a Kubernetes cluster that runs multi-tenant workloads. Several pods have been observed running as the root user inside their containers, which the engineer wants to prevent. The engineer applies a Pod Security Admission (PSA) label to the namespace that enforces the 'restricted' profile. Which of the following best describes the enforcement action taken by the 'restricted' profile when a pod violates its policy?
Medium10A GSEC consultant is hardening a Kubernetes cluster that runs multi-tenant workloads. A developer reports that a pod in the tenants namespace was able to read the contents of the kubelet's host filesystem at /var/lib/kubelet. The pod spec includes hostPath: {path: /var/lib/kubelet, type: Directory} under volumes and mounts it at /host. The cluster has Pod Security Admission enabled with the restricted profile enforced cluster-wide, but the tenants namespace was labeled pod-security.kubernetes.io/enforce: privileged to unblock a legacy job. Which action most directly closes this exposure?
Hard11Which of the following is the most effective way to prevent secrets (such as API keys) from being leaked via container images?
Easy12An enterprise development team is designing a Kubernetes cluster deployment where application containers frequently interact with cloud provider APIs. To minimize security blast radius, which architectural practice provides the most effective credential isolation per pod?
Medium13A developer is building a container image for a Python web application. During review, a security engineer notices the Dockerfile copies a .env file containing database credentials into the image and deletes it in a later RUN instruction. The engineer explains that this pattern still leaks the credentials. Which of the following best explains why the credentials remain exposed in the final image?
EasyOther domains
All GSEC exam domains
Frequently asked questions
- What does the Container Security domain cover on the GSEC exam?
- Be able to read a Dockerfile or Kubernetes manifest and choose the control that actually reduces host-kernel or credential exposure. The single most important thing: understand that image layers and default cluster permissions persist, so secrets and privilege must be removed at build time and enforced at runtime.
- How many questions are in this domain?
- This page lists all 13 Container Security questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Container Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.