Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A security team is deploying a Kubernetes cluster on a cloud platform and wants to harden the worker nodes against container breakout and privilege escalation. They are reviewing kubelet and container runtime configurations. Which TWO of the following measures are MOST effective at reducing the attack surface and preventing a compromised container from gaining node-level privileges? (Choose two.)

⚠ Common exam trap

The trap here is selecting detective controls like audit logging or general kubelet hardening instead of the preventive, workload-level restrictions that actually stop privilege escalation and breakout.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run containers with a read-only root filesystem and drop all Linux capabilities except those explicitly required.

Hardening worker nodes against container breakout requires preventive controls that limit what a compromised container can do. Running with a read-only root filesystem and dropping unnecessary Linux capabilities removes the tools and privileges needed for escalation. Enforcing the restricted Pod Security Standard via Pod Security Admission ensures workloads cannot run as root, cannot escalate privileges, and must meet seccomp and capability restrictions. Together these measures significantly reduce the attack surface and block common escape techniques.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable the kubelet read-only port and disable anonymous authentication to the kubelet API.

    Why it's wrong here

    Disabling anonymous authentication and the read-only port is a good hardening step for the kubelet API, but it primarily protects against unauthorized API access. It does not directly prevent a container that is already running from escalating privileges or breaking out to the node. Therefore it is not the most effective measure for the stated goal.

  • ✓

    Run containers with a read-only root filesystem and drop all Linux capabilities except those explicitly required.

    Why this is correct

    A read-only root filesystem prevents attackers from writing malicious binaries or modifying system files inside the container, and dropping unnecessary Linux capabilities removes the ability to perform privileged operations such as mounting filesystems or loading kernel modules. Together they significantly reduce the container's ability to escalate privileges or break out to the node.

  • ✗

    Configure the container runtime to use the overlay2 storage driver with a dedicated volume for each container.

    Why it's wrong here

    The overlay2 storage driver is a performance and layering mechanism, not a security boundary. Giving each container a dedicated volume may help with data separation but does not restrict capabilities, root execution, or filesystem writes. It does not materially prevent container breakout or privilege escalation on the node.

  • ✓

    Use a Pod Security Admission policy that enforces the restricted profile, which requires non-root execution and disallows privilege escalation.

    Why this is correct

    The restricted Pod Security Standard enforces non-root containers, disallows privilege escalation, drops capabilities, and requires seccomp profiles. Applying it via Pod Security Admission prevents workloads that could easily break out from being scheduled at all, directly reducing the attack surface and blocking common container escape vectors on the node.

  • ✗

    Enable audit logging on the Kubernetes API server and ship logs to a central SIEM for alerting.

    Why it's wrong here

    Audit logging provides visibility and forensic evidence, which is valuable for detection and compliance, but it is a detective control. It does not prevent a compromised container from escalating privileges or breaking out to the node. The question asks for measures that reduce the attack surface and prevent escalation, not merely detect it.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.