Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium

A security team is implementing a strategy to detect and respond to anomalous behavior within running containers in a Kubernetes cluster. They want to identify activities like unauthorized process execution, file system tampering, or unexpected network connections. Which category of security tools is best suited for this type of real-time monitoring and threat detection?

  1. AImage Vulnerability Scanners
  2. BDynamic Application Security Testing (DAST)
  3. CRuntime Security Monitoring
  4. DStatic Application Security Testing (SAST)
Show answer & explanation

Correct answer: C. Runtime Security Monitoring

Runtime security monitoring tools are specifically designed to observe and analyze the behavior of applications and containers as they execute. They can detect deviations from expected baselines, indicating potential compromises or malicious activities.

Why the other options are wrong

  • A. Image vulnerability scanners analyze container images for known vulnerabilities before deployment, not runtime behavior.
  • B. DAST tests applications by executing them and observing their behavior from the outside, typically for web applications, not internal container behavior.
  • D. SAST analyzes source code for vulnerabilities before runtime.

Runtime Security Monitoring

The continuous observation and analysis of running applications and containers to detect and respond to anomalous or malicious activities, such as unauthorized process execution, file system changes, or network connections.

  • Focuses on real-time threat detection.
  • Monitors process activity, file access, network connections.
  • Often uses behavioral baselining and rule-based detection.

Memory trick: Shift Left finds bugs early, Runtime catches the live action.

More Cloud Native Security questions