Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium

An organization is concerned about potential malicious activity within their Kubernetes cluster, specifically unauthorized file access or execution of unknown processes within running containers. They want to implement a solution that can detect and prevent such anomalies in real-time. Which type of security tool is best suited for this requirement?

  1. AContainer Image Vulnerability Scanner
  2. BDynamic Application Security Testing (DAST)
  3. CStatic Application Security Testing (SAST)
  4. DContainer Runtime Security (CRS) solution
Show answer & explanation

Correct answer: D. Container Runtime Security (CRS) solution

Container Runtime Security (CRS) solutions are designed to monitor and protect running containers. They detect and often prevent anomalous behavior, such as unauthorized file access, process execution, or network connections, by enforcing policies and behavioral baselines in real-time.

Why the other options are wrong

  • A. Container image vulnerability scanners analyze images for known CVEs *before* deployment, not for runtime anomalies.
  • B. DAST tests applications by executing them to find vulnerabilities, but typically focuses on web applications and doesn't provide real-time container process monitoring.
  • C. SAST analyzes source code for vulnerabilities before execution, not runtime behavior.

Container Runtime Security

Security measures and tools focused on protecting containers and their workloads while they are actively running in production.

  • Monitors container behavior for anomalies.
  • Enforces policies on processes, file access, and network activity.
  • Includes threat detection, intrusion prevention, and forensics capabilities.
  • Often uses eBPF for deep kernel visibility.

Memory trick: Different tools for different stages of security.

More Cloud Native Security questions