Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard
A security engineer is investigating a potential compromise. They suspect an attacker might be trying to exploit a kernel vulnerability from within a container. To mitigate such risks, the engineer wants to restrict the system calls a container can make to only those absolutely necessary for its operation. Which Linux security mechanism should they use?
- ALinux Capabilities
- BSELinux policies
- CAppArmor profiles
- DSeccomp (Secure Computing mode) profiles
Show answer & explanationAnswer & explanation
Correct answer: D. Seccomp (Secure Computing mode) profiles
Seccomp (Secure Computing mode) allows administrators to define a filter for system calls that a process can make. By creating a custom Seccomp profile, the engineer can precisely whitelist or blacklist specific system calls, thereby significantly reducing the attack surface for kernel exploits from within a container.
Why the other options are wrong
- A. Linux Capabilities allow breaking down the 'root' privilege into smaller, distinct units, but they don't provide the fine-grained control over individual system calls that Seccomp offers.
- B. SELinux is a comprehensive MAC system that controls resource access based on labels, but it's more complex and not primarily focused on granular system call filtering like Seccomp.
- C. AppArmor provides Mandatory Access Control (MAC) based on paths and process behavior, but it's less granular for specific system calls compared to Seccomp.
Seccomp (Secure Computing mode)
A Linux kernel feature that allows a process to restrict the set of system calls it can make, thereby reducing the attack surface and enhancing security.
- Filters system calls to whitelist or blacklist specific ones.
- Can be applied to containers to limit their kernel interaction.
- Significantly reduces vulnerability to kernel exploits.
Memory trick: Seccomp secures your container's system calls.