Courseiva

SSCP Systems and Application Security Practice Question

A security administrator is deploying a new web application on a Linux server. The application must be isolated from the host and other applications, and it must only be able to read its own configuration files. The administrator decides to use a container. Which of the following should the administrator implement to meet these requirements?

⚠ Common exam trap

The trap here is assuming that running a container as root or with privileged flags is necessary for it to function, when in fact it increases the attack surface and violates isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a read-only root filesystem and mount only the required configuration files as a read-only volume.

The requirement is to isolate the application and restrict it to reading only its own configuration files. A read-only root filesystem combined with read-only volume mounts for specific configuration files enforces this least-privilege model. Other options either grant excessive privileges or break functionality by removing all capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run the container as the root user to ensure it has permission to read the configuration files.

    Why it's wrong here

    Running as root inside the container increases the risk of privilege escalation and violates the principle of least privilege. It does not provide isolation from the host and could allow the container to access files beyond its own configuration if there is a misconfiguration.

  • ✗

    Run the container with the --privileged flag to ensure it has all necessary permissions.

    Why it's wrong here

    Using the --privileged flag gives the container almost all the capabilities of the host, including access to devices and kernel features. This directly violates the isolation requirement and would allow the container to read files outside its own configuration, making it an insecure choice for this scenario.

  • ✗

    Disable all Linux capabilities for the container to prevent any file access.

    Why it's wrong here

    Disabling all capabilities would prevent the container from performing even basic operations, such as reading files, which would break the application. The goal is to allow reading of its own configuration files, not to block all file access entirely.

  • ✓

    Use a read-only root filesystem and mount only the required configuration files as a read-only volume.

    Why this is correct

    A read-only root filesystem prevents the container from modifying its own files, and mounting only the necessary configuration files as read-only volumes enforces least privilege. This meets the requirement that the application can only read its own configuration files while being isolated from the host and other applications.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.