CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud security professional is evaluating container runtime security. Which Linux capability should be dropped from a container to prevent it from loading kernel modules?
⚠ Common exam trap
Candidates often confuse file-system capabilities (DAC_OVERRIDE, CHOWN) with kernel-level capabilities (SYS_MODULE, SYS_ADMIN); candidates who don't memorize the capability-to-operation mapping often pick a familiar-sounding name.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CAP_SYS_MODULE
CAP_SYS_MODULE is the Linux capability that permits a process to load and unload kernel modules via init_module() and delete_module() syscalls. Dropping it from a container's capability set prevents the containerized process from inserting malicious kernel code, which would otherwise be a direct path to host compromise. This is a standard hardening step in container security profiles (e.g., Docker's default seccomp/capability drop list).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CAP_DAC_OVERRIDE
Why it's wrong here
CAP_DAC_OVERRIDE bypasses file read, write and execute permission checks, so dropping it restricts filesystem access, not module loading. It is tempting because it is a genuinely dangerous capability worth removing, but kernel module loading is governed by CAP_SYS_MODULE.
- ✗
CAP_CHOWN
Why it's wrong here
CAP_CHOWN permits changing file ownership, so dropping it limits privilege changes over files rather than module loading. It is tempting because it appears in hardening guidance as a capability to remove, yet the kernel module loading operation is gated by CAP_SYS_MODULE.
- ✓
CAP_SYS_MODULE
Why this is correct
CAP_SYS_MODULE grants a process the ability to load and unload kernel modules via init_module and delete_module. Dropping it directly satisfies the stem's constraint: without this capability, the container cannot insert code into the host kernel, closing a critical container-escape and persistence vector.
- ✗
CAP_NET_RAW
Why it's wrong here
CAP_NET_RAW permits raw and packet sockets, so dropping it restricts network sniffing and spoofing, not module loading. It is tempting because it is a commonly dropped capability in container hardening, but loading kernel modules requires CAP_SYS_MODULE.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.