Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityEasy
A security engineer is implementing a strategy to prevent malicious processes within containers from making unauthorized system calls to the underlying Linux kernel. They want to restrict the set of available system calls for specific applications to only those absolutely necessary for their operation. Which Linux security mechanism is most effective for achieving this fine-grained control?
- ASeccomp (Secure Computing mode)
- BLinux Namespaces
- Ccgroups (Control Groups)
- DAppArmor
Show answer & explanationAnswer & explanation
Correct answer: A. Seccomp (Secure Computing mode)
Seccomp (Secure Computing mode) allows administrators to define a whitelist or blacklist of system calls that a process can make. This fine-grained control effectively limits the attack surface by preventing unauthorized interactions with the kernel.
Why the other options are wrong
- B. Linux Namespaces provide isolation for resources like PIDs, networks, and mount points, but don't restrict system calls.
- C. cgroups manage and limit resource usage (CPU, memory) for processes, not system calls.
- D. AppArmor is a mandatory access control (MAC) system that can restrict program capabilities, but Seccomp is more focused and granular for system calls.
Seccomp (Secure Computing mode)
A Linux kernel security feature that restricts the system calls a process can make, thereby reducing the attack surface and enhancing container security.
- Filters system calls (syscalls).
- Can whitelist or blacklist specific syscalls.
- Reduces the kernel attack surface for containerized applications.
Memory trick: Seccomp filters syscalls, securing the container's call-out.