CompTIA SecurityX (CAS-005)Security EngineeringHard

A security auditor is reviewing the hardening configuration of a Kubernetes cluster used for a highly sensitive application. The auditor notes that while Pod Security Admission (PSA) is enabled, there are still several pods running with elevated privileges (e.g., `privileged: true`, hostPath mounts) in non-administrative namespaces. The organization's policy prohibits such configurations for application pods. Which specific PSA enforcement level should be applied to these non-administrative namespaces to prevent the deployment of these insecure pods?

  1. APrivileged
  2. BRestricted
  3. CBaseline
  4. DEnforce
Show answer & explanation

Correct answer: B. Restricted

The 'Restricted' Pod Security Admission (PSA) enforcement level is designed to enforce heavily restricted Pod security standards, disallowing known privilege escalations and other insecure configurations. Specifically, it prevents pods from running as `privileged: true` or using `hostPath` mounts, which directly addresses the auditor's concern in non-administrative namespaces.

Why the other options are wrong

  • A. 'Privileged' is the least restrictive PSA mode, allowing all pods to run without restrictions, which is the opposite of the requirement.
  • C. 'Baseline' prevents known privilege escalations but allows some common configurations (e.g., hostPath) that 'Restricted' would deny, making it insufficient for 'highly sensitive' applications.
  • D. While 'Enforce' is a mode, it's not a security level. The security levels are Privileged, Baseline, and Restricted, which can be applied in Enforce, Audit, or Warn modes.

Pod Security Admission (PSA) Levels

Kubernetes' built-in admission controller for enforcing Pod Security Standards (PSS) at different levels (Privileged, Baseline, Restricted) to control the security posture of pods.

  • Enforces PSS at admission time.
  • Three levels: Privileged, Baseline, Restricted.
  • Applied per namespace with 'enforce', 'audit', 'warn' modes.

Memory trick: PSA: Privileged, BASELINE, RESTRICTED, like security levels.

More Security Engineering questions