CCSP Cloud Platform and Infrastructure Security Practice Question
A security auditor is reviewing a Kubernetes cluster and identifies that containers are running as root with full Linux capabilities. Which TWO security measures would help mitigate container escape risks in this environment?
⚠ Common exam trap
The trap is that 'privileged container' and 'host networking' sound like advanced features that might improve security, when in fact they are the exact misconfigurations that enable container escapes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the container to run as a non-root user
Option A is correct because configuring the container to run as a non-root user (e.g., via securityContext.runAsUser or runAsNonRoot: true) removes the root privileges that an attacker could leverage to exploit kernel vulnerabilities or access host resources during a container escape attempt. Option D is correct because dropping all Linux capabilities and then adding back only those explicitly required (using securityContext.capabilities.drop: ["ALL"]) follows the principle of least privilege, eliminating dangerous capabilities like CAP_SYS_ADMIN, CAP_NET_ADMIN, and CAP_SYS_PTRACE that are commonly abused in container escape techniques. Option B is incorrect because enabling host networking mode actually increases risk by removing network namespace isolation, allowing the container to access host network interfaces and services directly. Option C is incorrect because privileged containers disable nearly all security mechanisms (seccomp, AppArmor, capability restrictions) and grant full access to host devices, dramatically worsening escape risk. Option E is incorrect because mounting the host filesystem as read-write gives the container direct write access to host files, enabling tampering with system binaries or configuration to facilitate escape and persistence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set the container to run as a non-root user
Why this is correct
Running the container as a non-root user removes UID 0 inside the container, so a breakout attempt lands with unprivileged rights on the host and cannot modify protected files or kernel interfaces. This directly mitigates the root-with-full-capabilities risk the auditor identified.
- ✗
Enable host networking mode
Why it's wrong here
Host networking removes the container's isolated network namespace, letting it share the node's interfaces and reach services bound to localhost, which widens rather than narrows escape paths. It is tempting because it simplifies pod-to-node communication, and would be correct when a workload genuinely needs node-level network performance.
- ✗
Use a privileged container
Why it's wrong here
A privileged container grants all Linux capabilities and unrestricted device access, directly amplifying the escape risk already identified rather than mitigating it. It is tempting because it resolves permission errors quickly during troubleshooting, and would be correct only for trusted node-level agents that must manage host hardware.
- ✓
Drop all Linux capabilities except those needed
Why this is correct
Dropping all Linux capabilities except those genuinely required strips privileges such as CAP_SYS_ADMIN and CAP_NET_ADMIN, which are the primary enablers of container escape and host compromise. This directly reduces the attack surface created by containers holding full capabilities.
- ✗
Mount the host filesystem as read-write
Why it's wrong here
Mounting the host filesystem read-write gives a root container direct write access to node binaries and configuration, enabling persistence and privilege escalation after escape. It is tempting because it simplifies logging or configuration updates, and would be correct read-only for monitoring agents needing host metrics.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.