SSCP Systems and Application Security Practice Question
A healthcare organization is deploying a containerized patient records application on Kubernetes. The security team wants to prevent a compromised container from accessing the underlying node's filesystem and from escalating privileges. Which Kubernetes control should be configured to restrict the container's capabilities and prevent privilege escalation?
⚠ Common exam trap
Many candidates confuse network isolation or resource limits with process-level privilege restriction, when only securityContext capability and privilege escalation settings control what the container process can do on the host.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the pod's securityContext to allowPrivilegeEscalation: false and drop all Linux capabilities.
Restricting a container's privileges requires configuring its securityContext to prevent privilege escalation and to drop unnecessary Linux capabilities. These settings directly limit what the container process can do on the host, including mounting filesystems or using privileged system calls. Network policies, privileged pod security profiles, and resource quotas address different concerns and do not prevent host filesystem access or privilege escalation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a resource quota that limits CPU and memory for the pod.
Why it's wrong here
ResourceQuota limits compute resource consumption to prevent denial of service through resource exhaustion. It has no effect on filesystem mounts, Linux capabilities, or privilege escalation. A compromised container could still access host paths and escalate privileges within its resource limits, so this control does not mitigate the stated threats.
- ✗
Enable PodSecurityPolicy with the privileged profile applied to the namespace.
Why it's wrong here
A privileged PodSecurityPolicy actually grants broad permissions, including host access and elevated capabilities, which is the opposite of what is needed. Privileged profiles are intended for system-level pods, not patient record workloads. Using this profile would increase the attack surface rather than restrict the container's access to the node filesystem.
- ✓
Set the pod's securityContext to allowPrivilegeEscalation: false and drop all Linux capabilities.
Why this is correct
The securityContext fields allowPrivilegeEscalation and capabilities directly control whether a process can gain more privileges than its parent and which Linux capabilities are available. Setting allowPrivilegeEscalation to false blocks setuid and similar escalation paths, while dropping capabilities removes the ability to perform privileged operations such as mounting filesystems or modifying kernel parameters. This precisely mitigates the described risk.
- ✗
Configure a NetworkPolicy that denies all ingress and egress traffic to the pod.
Why it's wrong here
NetworkPolicy controls network traffic between pods and external endpoints. It does not restrict filesystem access or process capabilities within the container. A compromised container could still mount host paths or escalate privileges locally even with all network traffic blocked, so this control does not address the stated risk.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.