Courseiva

GSEC · topic practice

Container Security practice questions

This domain covers securing containerized workloads and orchestrators on Linux hosts. GSEC questions present Dockerfiles, Kubernetes manifests, and multi-tenant cluster scenarios, then ask you to pick the control that best limits blast radius, protects the host kernel, or prevents credential exposure in images and running pods.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
19 questionsDomain: Container Security

What the exam tests

What to know about Container Security

Be able to read a Dockerfile or Kubernetes manifest and choose the control that actually reduces host-kernel or credential exposure. The single most important thing: understand that image layers and default cluster permissions persist, so secrets and privilege must be removed at build time and enforced at runtime.

Applying Kubernetes Pod Security Standards, seccomp, AppArmor, and read-only root filesystems to limit container privilege

Using Dockerfile multi-stage builds, .dockerignore, and non-root USER to keep secrets and build artifacts out of images

Configuring Kubernetes RBAC, NetworkPolicy, and service accounts to isolate multi-tenant namespaces and restrict kubelet access

Hardening the container runtime with user namespaces, dropped Linux capabilities, and rootless or gVisor sandboxing

Watch out for

Common Container Security exam traps

  • ▸Believing deleting a secret in a later Dockerfile layer removes it; earlier layers still contain the credential and remain pullable.
  • ▸Assuming namespace separation alone isolates tenants, while default service accounts, hostPath mounts, or missing NetworkPolicy still allow lateral access.
  • ▸Confusing image scanning with runtime protection; a clean scan does not stop a compromised container from abusing host kernel interfaces.

Practice set

Container Security questions

19 questions · select your answer, then reveal the explanation

Which TWO of the following configurations are considered best practices for securing the Docker daemon?

Refer to the exhibit. An engineer is reviewing a Dockerfile for a microservice. Which security issue is present in this configuration?

Network Topology
RUN apk addno-cache curlFROM alpine:latestUSER 1000:1000COPY ./app /appCMD ["/app/run.sh"]

Which THREE of the following are primary components of a comprehensive container security strategy?

A GSEC analyst is reviewing a Kubernetes Deployment manifest for an internet-facing payment service. The pod spec sets allowPrivilegeEscalation to false, runAsNonRoot to true, and drops all Linux capabilities, but the container image is tagged myregistry/paymentsvc:latest and the imagePullPolicy is left at its default. The analyst wants to harden the workload so that a compromised registry account cannot silently swap in a malicious image on the next pod restart. Which change best mitigates this supply-chain risk?

A security engineer is configuring a Kubernetes cluster and wants to enforce that all pods must run with a read-only root filesystem. Which Kubernetes admission controller should be used to validate this requirement?

A security analyst is reviewing the security posture of a Kubernetes cluster that runs production workloads. The analyst wants to reduce the attack surface of containers running in the cluster by applying Linux kernel-level isolation controls. Which TWO of the following mechanisms, when configured, restrict the system calls a container process can make to the host kernel? (Choose two.)

Question 7mediummultiple choice
Study the full AAA explanation →

An enterprise development team is designing a Kubernetes cluster deployment where application containers frequently interact with cloud provider APIs. To minimize security blast radius, which architectural practice provides the most effective credential isolation per pod?

A security engineer wants to ensure that container images are not modified after they are built and pushed to a registry. Which mechanism provides the strongest assurance of image integrity and authenticity?

When designing a secure container orchestration strategy, which approach best minimizes the impact of a compromised container on the host kernel?

Which of the following is the most effective way to prevent secrets (such as API keys) from being leaked via container images?

Question 11mediummultiple choice
Read the full Container Security explanation →

Refer to the exhibit. What is the security impact of the provided Kubernetes security context configuration?

Exhibit

apiVersion: v1
kind: Pod
metadata:
  name: secure-pod
spec:
  containers:
  - name: app
    image: myapp:1.0
    securityContext:
      runAsNonRoot: true
      allowPrivilegeEscalation: false

A GSEC consultant is hardening a Kubernetes cluster that runs multi-tenant workloads. A developer reports that a pod in the tenants namespace was able to read the contents of the kubelet's host filesystem at /var/lib/kubelet. The pod spec includes hostPath: {path: /var/lib/kubelet, type: Directory} under volumes and mounts it at /host. The cluster has Pod Security Admission enabled with the restricted profile enforced cluster-wide, but the tenants namespace was labeled pod-security.kubernetes.io/enforce: privileged to unblock a legacy job. Which action most directly closes this exposure?

Question 13mediummultiple choice
Read the full Container Security explanation →

A GSEC candidate is reviewing a Docker Compose file for a web application. The file includes a service definition that mounts the Docker socket into the container. What is the primary security risk of this configuration?

A security analyst is examining a Kubernetes Pod specification that includes the following securityContext: runAsUser: 0. What is the security implication of this setting?

Question 15mediummultiple choice
Read the full Container Security explanation →

A security engineer is hardening a Kubernetes cluster that runs multi-tenant workloads. Several pods have been observed running as the root user inside their containers, which the engineer wants to prevent. The engineer applies a Pod Security Admission (PSA) label to the namespace that enforces the 'restricted' profile. Which of the following best describes the enforcement action taken by the 'restricted' profile when a pod violates its policy?

A developer is building a container image for a Python web application. During review, a security engineer notices the Dockerfile copies a .env file containing database credentials into the image and deletes it in a later RUN instruction. The engineer explains that this pattern still leaks the credentials. Which of the following best explains why the credentials remain exposed in the final image?

A platform team runs a Kubernetes cluster where a container was compromised through a remote code execution flaw in a web application. The attacker attempted to read the service account token, query the API server, and list secrets in the namespace. The team wants to reduce the impact of such a compromise in the future. Which of the following changes most directly limits what the compromised pod's service account can do against the API server?

Question 18mediummultiple choice
Read the full Container Security explanation →

A security engineer is evaluating a container runtime for a production Kubernetes cluster. The requirement is that the runtime must not share the host kernel with containers, providing stronger isolation than standard runc-based containers. Which of the following runtimes best satisfies this requirement?

A GSEC analyst is reviewing the deployment pipeline for a containerized Node.js service. The Dockerfile contains a layer that runs `curl -fsSL https://example.com/install.sh | sh` during the build, before the image is pushed to an internal registry. The registry enforces vulnerability scanning, and the image is deployed to a Kubernetes cluster with a restrictive NetworkPolicy. Which of the following is the primary supply chain risk introduced by this Dockerfile instruction?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Container Security sessions

Start a Container Security only practice session

Every question in these sessions is drawn from the Container Security domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Container Security?
Be able to read a Dockerfile or Kubernetes manifest and choose the control that actually reduces host-kernel or credential exposure. The single most important thing: understand that image layers and default cluster permissions persist, so secrets and privilege must be removed at build time and enforced at runtime.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Container Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Container Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.
GIAC Security Essentials Container Security Practice Questions with Explanations | Courseiva