Courseiva
Container Security →mediumMultiple Choice

GSEC Container Security Practice Question

When designing a secure container orchestration strategy, which approach best minimizes the impact of a compromised container on the host kernel?

⚠ Common exam trap

Candidates often select standard namespace isolation or network policies, which do not protect the host kernel from system call exploitation, the primary method for container breakouts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a specialized container runtime like gVisor to intercept system calls.

Kernel vulnerabilities are a primary vector for container escapes. By using technologies like gVisor or Kata Containers, the container environment uses a hardened kernel or a separate micro-VM, providing an additional layer of isolation. Standard containers share the host kernel directly; if the kernel is exploited via a system call, the attacker can break out of the container boundary entirely, leading to full system compromise of the underlying host node.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable all kernel modules on the host operating system.

    Why it's wrong here

    Disabling all kernel modules is generally impractical, as many are required for network and storage operations. Furthermore, it does not prevent direct system call exploitation against the core kernel. While reducing modules can shrink the surface, it does not provide the robust isolation required for untrusted containerized workloads.

  • ✓

    Use a specialized container runtime like gVisor to intercept system calls.

    Why this is correct

    gVisor acts as a user-space kernel that intercepts and handles system calls. By limiting the number of system calls that reach the host kernel, it drastically reduces the available attack surface for privilege escalation and kernel exploits, effectively containing the potential damage from a compromised application within the guest.

  • ✗

    Increase the memory limit for every container in the cluster.

    Why it's wrong here

    Adjusting resource limits is a capacity planning and availability task, not a security isolation control. Increasing memory does not prevent a malicious actor from exploiting vulnerabilities within the application code or the kernel. It may even provide more resources for an attacker to perform malicious activities like crypto-mining.

  • ✗

    Run all containers with the --privileged flag to ensure compatibility.

    Why it's wrong here

    The --privileged flag disables almost all security isolation features, granting the container full access to host devices and kernel capabilities. This is a severe security risk that enables trivial container escapes and host takeover. It should only be used in highly specific, trusted scenarios and never for general applications.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.