CCSP Cloud Platform and Infrastructure Security Practice Question
A container runtime is configured to drop all Linux capabilities, use a read-only root filesystem, and apply a Seccomp profile. Which primary security goal does this configuration achieve?
⚠ Common exam trap
CCSP often tests the confusion between runtime hardening controls and other security goals — candidates may pick immutability or image integrity when the combination of capabilities, read-only FS, and Seccomp specifically targets escape prevention.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prevention of container escape
Dropping all Linux capabilities, using a read-only root filesystem, and applying a Seccomp profile collectively harden the container against privilege escalation and syscall-based attacks that are commonly used in container escape techniques. These controls limit what a compromised process can do, making it much harder to break out of the container and access the host. Thus, the primary security goal is prevention of container escape.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Image integrity verification
Why it's wrong here
Dropping capabilities, read-only root filesystems and Seccomp profiles constrain what a running container process may do, limiting kernel attack surface and privilege escalation; they do not hash or verify image content. Image integrity verification is tempting because it is also container security, but it requires signature checking, not runtime hardening.
- ✗
Ensuring immutability of containers
Why it's wrong here
Dropping capabilities, read-only root and Seccomp restrict syscalls and runtime behaviour, which is hardening against exploitation, not immutability. Immutability means containers are never modified after build and are replaced rather than patched; that is achieved through image digests, immutable registries and redeployment pipelines, not capability or syscall controls.
- ✓
Prevention of container escape
Why this is correct
Dropping all Linux capabilities removes the privileges an attacker needs to break out of the container's namespace isolation, while the read-only root filesystem and Seccomp profile block the syscalls and filesystem writes that privilege-escalation exploits rely on. Together these harden the container boundary against escape.
- ✗
Network segmentation between pods
Why it's wrong here
Dropping capabilities, a read-only root filesystem and Seccomp profiles all constrain what a process may do inside its container, which is workload hardening, not network segmentation. Segmentation is achieved with network policies, service meshes or namespace isolation controlling pod-to-pod traffic; it would be the answer if the stem described restricting lateral movement between workloads.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.