Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard

A security engineer is investigating a potential compromise. They suspect an attacker might be trying to exploit a kernel vulnerability from within a container. To mitigate such risks, the engineer wants to restrict the system calls a container can make to only those absolutely necessary for its operation. Which Linux security mechanism should they use?

  1. ALinux Capabilities
  2. BSELinux policies
  3. CAppArmor profiles
  4. DSeccomp (Secure Computing mode) profiles
Show answer & explanation

Correct answer: D. Seccomp (Secure Computing mode) profiles

Seccomp (Secure Computing mode) allows administrators to define a filter for system calls that a process can make. By creating a custom Seccomp profile, the engineer can precisely whitelist or blacklist specific system calls, thereby significantly reducing the attack surface for kernel exploits from within a container.

Why the other options are wrong

  • A. Linux Capabilities allow breaking down the 'root' privilege into smaller, distinct units, but they don't provide the fine-grained control over individual system calls that Seccomp offers.
  • B. SELinux is a comprehensive MAC system that controls resource access based on labels, but it's more complex and not primarily focused on granular system call filtering like Seccomp.
  • C. AppArmor provides Mandatory Access Control (MAC) based on paths and process behavior, but it's less granular for specific system calls compared to Seccomp.

Seccomp (Secure Computing mode)

A Linux kernel feature that allows a process to restrict the set of system calls it can make, thereby reducing the attack surface and enhancing security.

  • Filters system calls to whitelist or blacklist specific ones.
  • Can be applied to containers to limit their kernel interaction.
  • Significantly reduces vulnerability to kernel exploits.

Memory trick: Seccomp secures your container's system calls.

More Cloud Native Security questions