CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security engineer is configuring a new Kubernetes cluster for a highly sensitive application. The organization's policy dictates that containers must run with the minimum necessary privileges, and specifically, they should not be able to gain root access, escalate privileges, or access sensitive host paths. Which Kubernetes security primitive should be primarily leveraged to enforce these runtime security constraints on pods?

  1. APod Security Admission (PSA)
  2. BResource Quotas
  3. CHorizontal Pod Autoscaler (HPA)
  4. DNetwork Policies
Show answer & explanation

Correct answer: A. Pod Security Admission (PSA)

Pod Security Admission (PSA) is the native Kubernetes admission controller specifically designed to enforce Pod Security Standards (PSS) on pods. PSS defines three security levels (Privileged, Baseline, Restricted) that address common container security concerns, including preventing root access, privilege escalation, and access to sensitive host paths. By configuring PSA to enforce the 'Restricted' or 'Baseline' profile, the security engineer can ensure that pods adhere to the organization's runtime security constraints.

Why the other options are wrong

  • B. Resource Quotas manage the consumption of computing resources (CPU, memory) by namespaces, not the security context or privileges of pods.
  • C. Horizontal Pod Autoscaler (HPA) automatically scales the number of pods in a deployment based on observed CPU utilization or other metrics, unrelated to security privileges.
  • D. Network Policies control network communication between pods and other network endpoints, not their internal runtime privileges or host access.

Pod Security Admission (PSA)

Pod Security Admission (PSA) is a built-in Kubernetes admission controller that enforces the Pod Security Standards (PSS) on pods, allowing administrators to define different security profiles for namespaces.

  • Replaced Pod Security Policies (PSPs) in Kubernetes 1.25+.
  • Enforces 'Privileged', 'Baseline', or 'Restricted' security standards.
  • Prevents common privilege escalation and container breakout attacks.
  • Controls capabilities, host access, volume types, and user IDs for pods.

Memory trick: PSA Protects Pods from Privilege Problems

More Security Engineering questions