Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium
A security engineer is tasked with preventing privilege escalation attacks within containers in a Kubernetes environment. Specifically, they want to ensure that no container can gain root privileges on the host node or access sensitive kernel features. Which Linux security primitive is fundamental to isolating processes and their capabilities within a container?
- Acgroups
- Biptables
- CSELinux
- Dnamespaces
Show answer & explanationAnswer & explanation
Correct answer: D. namespaces
Linux namespaces are the core mechanism that provides process isolation for containers, giving each container its own view of system resources like PIDs, network interfaces, and user IDs, preventing escape to the host's root.
Why the other options are wrong
- A. cgroups (control groups) manage resource allocation, not isolation of system views.
- B. iptables is a firewall tool for network packet filtering, not process isolation.
- C. SELinux is a mandatory access control system, providing fine-grained permissions, but namespaces create the initial isolation boundary.
Linux Namespaces
A feature of the Linux kernel that partitions kernel resources such that a process or set of processes has its own isolated view of the global system resources.
- Fundamental for container isolation.
- Each namespace type isolates a specific resource (PID, network, user, mount, UTS, IPC).
- Prevents processes from seeing or interacting with resources outside their namespace.
Memory trick: Namespaces create container worlds.