Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A financial services firm runs a multi-tenant SaaS platform on AWS. A penetration test reveals that a compromised container on one tenant's node was able to read environment variables belonging to another tenant's pods scheduled on the same node. The platform uses Kubernetes with default settings, and pods are not configured with any security context. Which control most directly addresses this isolation failure?

⚠ Common exam trap

The trap here is assuming that pod-level hardening or network policies solve a node-level namespace isolation problem; those controls harden a single workload but do not separate tenants sharing a kernel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy each tenant's workloads using a dedicated container runtime sandbox such as gVisor or Kata Containers, or enforce pod-level isolation with user namespaces and separate runtime classes.

When containers share a node without strong isolation, one workload can sometimes observe another's process environment or runtime metadata. Enforcing dedicated sandboxes such as gVisor or Kata Containers, or isolating with user namespaces and distinct runtime classes, creates a hard boundary between tenants. This is the control that directly addresses the cross-tenant environment variable exposure described.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure pod security contexts to run containers as non-root with readOnlyRootFilesystem and drop all Linux capabilities.

    Why it's wrong here

    Hardening the container itself reduces the impact of a compromise but does not stop a container from inspecting the shared process namespace or runtime metadata of sibling pods. The cross-tenant leak here stems from shared node-level namespaces, which pod-level hardening alone cannot close. Additional isolation boundaries at the pod or runtime level are required.

  • ✗

    Encrypt all Kubernetes Secrets at rest using a KMS provider and rotate the encryption keys quarterly.

    Why it's wrong here

    Encrypting Secrets at rest protects data on the etcd volume but does nothing once the secret is mounted into a pod as an environment variable or file. The penetration test exploited runtime visibility between containers, not storage exposure. Key rotation addresses a different threat model and would not have prevented the observed cross-tenant read.

  • ✗

    Enable Kubernetes Network Policies that deny all ingress and egress by default between namespaces.

    Why it's wrong here

    Network Policies control pod-to-pod network traffic and would not prevent a process from reading environment variables of another pod on the same node. Environment variables are exposed through the container runtime and process namespace, not the network stack, so network isolation leaves this attack path open. The failure described is a workload isolation issue, not a network segmentation issue.

  • ✓

    Deploy each tenant's workloads using a dedicated container runtime sandbox such as gVisor or Kata Containers, or enforce pod-level isolation with user namespaces and separate runtime classes.

    Why this is correct

    The leak occurred because containers on the same node share kernel and, in some configurations, process namespaces that allow visibility into sibling workloads. Stronger isolation boundaries such as gVisor, Kata Containers, or user namespaces with distinct runtime classes prevent one tenant's container from observing another's process environment. This directly closes the cross-tenant visibility path observed by the penetration test.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.