Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

During a security assessment of a Kubernetes cluster, you discover that a container is running as root with privileged mode enabled. Which of the following is the most critical risk associated with this configuration?

⚠ Common exam trap

CCSP often tests the misconception that network policy bypass or resource limits are the primary risks of privileged containers, when the most critical risk is container escape leading to host compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Potential for container escape to the host OS

Running a container as root with privileged mode enabled grants the container almost all the capabilities of the host's root user, including access to host devices and kernel features. This significantly increases the attack surface, making it easier for an attacker to exploit kernel vulnerabilities or misconfigurations to escape the container and gain control of the host OS. While other risks exist, container escape is the most critical because it compromises the entire node and potentially the whole cluster.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network policy bypass allowing unauthorized pod communication

    Why it's wrong here

    Network policy bypass concerns pod-to-pod traffic governed by CNI policy, not the container's privilege level. It is tempting because privileged pods can alter iptables, but the critical risk of root plus privileged mode is direct host kernel and device access, enabling container escape and full node compromise.

  • ✓

    Potential for container escape to the host OS

    Why this is correct

    Privileged mode grants the container broad Linux capabilities and direct access to host devices, so a compromise lets an attacker break out of the container namespace and execute code on the host OS, escalating from workload compromise to full node takeover.

  • ✗

    Increased memory consumption due to lack of resource limits

    Why it's wrong here

    Memory consumption stems from absent resource limits, a separate misconfiguration unrelated to root or privileged mode. It is tempting because privileged containers can exhaust host resources, yet the critical risk here is host kernel access: privileged mode grants capabilities that permit container escape and node compromise.

  • ✗

    Inability to mount volumes for persistent storage

    Why it's wrong here

    Privileged mode actually broadens volume mounting capabilities rather than preventing it, so this inverts the real effect. It is tempting because storage misconfiguration is a common Kubernetes issue, but the stem asks about root with privileged mode, whose critical risk is host-level access enabling container escape.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.