GSEC Container Security Practice Question
When designing a secure container orchestration strategy, which approach best minimizes the impact of a compromised container on the host kernel?
⚠ Common exam trap
Candidates often select standard namespace isolation or network policies, which do not protect the host kernel from system call exploitation, the primary method for container breakouts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a specialized container runtime like gVisor to intercept system calls.
Kernel vulnerabilities are a primary vector for container escapes. By using technologies like gVisor or Kata Containers, the container environment uses a hardened kernel or a separate micro-VM, providing an additional layer of isolation. Standard containers share the host kernel directly; if the kernel is exploited via a system call, the attacker can break out of the container boundary entirely, leading to full system compromise of the underlying host node.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable all kernel modules on the host operating system.
Why it's wrong here
Disabling all kernel modules is generally impractical, as many are required for network and storage operations. Furthermore, it does not prevent direct system call exploitation against the core kernel. While reducing modules can shrink the surface, it does not provide the robust isolation required for untrusted containerized workloads.
- ✓
Use a specialized container runtime like gVisor to intercept system calls.
Why this is correct
gVisor acts as a user-space kernel that intercepts and handles system calls. By limiting the number of system calls that reach the host kernel, it drastically reduces the available attack surface for privilege escalation and kernel exploits, effectively containing the potential damage from a compromised application within the guest.
- ✗
Increase the memory limit for every container in the cluster.
Why it's wrong here
Adjusting resource limits is a capacity planning and availability task, not a security isolation control. Increasing memory does not prevent a malicious actor from exploiting vulnerabilities within the application code or the kernel. It may even provide more resources for an attacker to perform malicious activities like crypto-mining.
- ✗
Run all containers with the --privileged flag to ensure compatibility.
Why it's wrong here
The --privileged flag disables almost all security isolation features, granting the container full access to host devices and kernel capabilities. This is a severe security risk that enables trivial container escapes and host takeover. It should only be used in highly specific, trusted scenarios and never for general applications.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.