Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium

A security engineer is implementing a strategy to prevent malicious processes from making unexpected system calls within a container. They want to define a whitelist of allowed system calls for specific applications, blocking any calls outside this predefined set. Which Linux security mechanism is specifically designed for this purpose?

  1. AAppArmor
  2. BSeccomp (Secure Computing mode)
  3. CLinux Namespaces
  4. Dcgroups
Show answer & explanation

Correct answer: B. Seccomp (Secure Computing mode)

Seccomp (Secure Computing mode) allows administrators to define a filter for system calls that a process can make. This enables whitelisting or blacklisting specific syscalls, effectively reducing the attack surface by preventing unauthorized kernel interactions.

Why the other options are wrong

  • A. AppArmor is a Mandatory Access Control system that can enforce policies on file access, network, and capabilities, but Seccomp is more granular for syscall filtering.
  • C. Namespaces isolate resources but don't control which system calls can be made.
  • D. cgroups control resource limits but not system call access.

Seccomp (Secure Computing mode)

A Linux kernel feature that allows a process to restrict the system calls it can make, enabling the creation of whitelists or blacklists of allowed syscalls to reduce the attack surface.

  • Filters system calls at the kernel level.
  • Can be used to whitelist or blacklist syscalls.
  • Reduces the attack surface of containers.
  • Implemented via `seccomp` profiles in Kubernetes Pod Security Context.

Memory trick: Seccomp filters syscalls securely.

More Cloud Native Security questions