Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium
A security team is implementing a strategy to detect and prevent unauthorized changes or malicious activities within running containers in a Kubernetes cluster. They want a solution that can monitor system calls, file access, and network activity to identify deviations from expected behavior. Which security control directly addresses this requirement?
- AContainer Runtime Security
- BDynamic Application Security Testing (DAST)
- CSoftware Bill of Materials (SBOM)
- DStatic Application Security Testing (SAST)
Show answer & explanationAnswer & explanation
Correct answer: A. Container Runtime Security
Container Runtime Security specifically focuses on monitoring and protecting containers during their execution phase, detecting anomalous behavior like unexpected system calls or file access. This is crucial for identifying and preventing active threats.
Why the other options are wrong
- B. DAST tests applications in a running state, but typically for web application vulnerabilities, not general container runtime integrity.
- C. SBOM lists components in software but does not actively monitor runtime behavior.
- D. SAST analyzes source code for vulnerabilities before runtime, not during.
Container Runtime Security
The practice of protecting containers during their execution phase by monitoring for suspicious activities, enforcing policies, and preventing unauthorized actions.
- Focuses on active threat detection.
- Monitors system calls, file access, network activity.
- Can enforce policies to stop malicious behavior.
Memory trick: Runtime security watches actively.