CRISC Information Technology and Security Practice Question
A risk manager is assessing the security posture of a containerized application deployment in a public cloud. The organization uses Kubernetes for orchestration. Which TWO of the following are the MOST significant risks specific to this environment? (Choose two.)
⚠ Common exam trap
The trap here is being misled by statements that assume automatic security controls, such as automatic network segmentation or default RBAC, rather than recognizing the actual risks of unpatched images and unencrypted secrets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Container images may contain vulnerable dependencies that are not patched regularly.
The most significant risks are vulnerable container images and unencrypted Kubernetes secrets in etcd. Vulnerable images can introduce exploitable flaws, while unencrypted secrets can be read by attackers with etcd access. Both are specific to containerized Kubernetes environments and require proactive controls such as image scanning and etcd encryption. The other options describe misconceptions or false assumptions that do not represent the primary risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Container images may contain vulnerable dependencies that are not patched regularly.
Why this is correct
Container images often include third-party libraries and base images that may have known vulnerabilities. If not scanned and patched regularly, these vulnerabilities can be exploited to compromise the container and potentially the host. This is a significant risk in containerized environments because images are immutable and may be reused across deployments, propagating vulnerabilities.
- ✗
Container orchestration platforms automatically enforce network segmentation, eliminating the risk of lateral movement.
Why it's wrong here
Kubernetes does not automatically enforce network segmentation; network policies must be defined and applied. Without proper network policies, containers can communicate freely, enabling lateral movement. Assuming automatic segmentation is a dangerous misconception. This option is incorrect because it describes a false sense of security rather than an actual risk, but the risk of lateral movement exists if network policies are not configured.
- ✗
The cloud provider's shared responsibility model means the organization is not responsible for the security of the underlying nodes.
Why it's wrong here
In a shared responsibility model, the cloud provider secures the infrastructure, but the organization is responsible for securing the nodes, containers, and applications it deploys. Misunderstanding this model can lead to unpatched nodes or misconfigurations. However, this is a misconception rather than a specific risk; the actual risk is that the organization may neglect its responsibilities, but it is not the most significant technical risk compared to image vulnerabilities and unencrypted secrets.
- ✓
Kubernetes secrets are stored unencrypted by default in etcd, allowing attackers with access to etcd to retrieve sensitive data.
Why this is correct
By default, Kubernetes stores secrets in etcd without encryption. An attacker who gains access to etcd can read all secrets, including passwords and tokens. This is a critical risk specific to Kubernetes deployments. Enabling encryption at rest for etcd is a necessary mitigation to protect sensitive information.
- ✗
Kubernetes RBAC is enabled by default and cannot be misconfigured, so access control risks are minimal.
Why it's wrong here
Kubernetes RBAC is not enabled by default in all distributions and can be misconfigured, leading to excessive permissions. Overly permissive roles or bindings can allow attackers to escalate privileges. This option is incorrect because it falsely claims RBAC is always enabled and secure. In reality, RBAC misconfiguration is a significant risk in Kubernetes environments.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.