Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A container runtime is configured to drop all Linux capabilities, use a read-only root filesystem, and apply a Seccomp profile. Which primary security goal does this configuration achieve?

⚠ Common exam trap

CCSP often tests the confusion between runtime hardening controls and other security goals — candidates may pick immutability or image integrity when the combination of capabilities, read-only FS, and Seccomp specifically targets escape prevention.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prevention of container escape

Dropping all Linux capabilities, using a read-only root filesystem, and applying a Seccomp profile collectively harden the container against privilege escalation and syscall-based attacks that are commonly used in container escape techniques. These controls limit what a compromised process can do, making it much harder to break out of the container and access the host. Thus, the primary security goal is prevention of container escape.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Image integrity verification

    Why it's wrong here

    Dropping capabilities, read-only root filesystems and Seccomp profiles constrain what a running container process may do, limiting kernel attack surface and privilege escalation; they do not hash or verify image content. Image integrity verification is tempting because it is also container security, but it requires signature checking, not runtime hardening.

  • ✗

    Ensuring immutability of containers

    Why it's wrong here

    Dropping capabilities, read-only root and Seccomp restrict syscalls and runtime behaviour, which is hardening against exploitation, not immutability. Immutability means containers are never modified after build and are replaced rather than patched; that is achieved through image digests, immutable registries and redeployment pipelines, not capability or syscall controls.

  • ✓

    Prevention of container escape

    Why this is correct

    Dropping all Linux capabilities removes the privileges an attacker needs to break out of the container's namespace isolation, while the read-only root filesystem and Seccomp profile block the syscalls and filesystem writes that privilege-escalation exploits rely on. Together these harden the container boundary against escape.

  • ✗

    Network segmentation between pods

    Why it's wrong here

    Dropping capabilities, a read-only root filesystem and Seccomp profiles all constrain what a process may do inside its container, which is workload hardening, not network segmentation. Segmentation is achieved with network policies, service meshes or namespace isolation controlling pod-to-pod traffic; it would be the answer if the stem described restricting lateral movement between workloads.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.