Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium

A security operations team wants to implement a strategy to detect and respond to suspicious activities within their Kubernetes cluster, such as unauthorized process execution, file integrity violations, or attempts to access sensitive kernel modules from containers. They need a tool that can monitor container runtime behavior and generate alerts for anomalies. Which type of security solution is most appropriate for this requirement?

  1. AStatic Application Security Testing (SAST) tool
  2. BRuntime Security Monitoring and Enforcement tool
  3. CContainer Image Vulnerability Scanner
  4. DNetwork Intrusion Detection System (NIDS)
Show answer & explanation

Correct answer: B. Runtime Security Monitoring and Enforcement tool

Runtime Security Monitoring and Enforcement tools (e.g., Falco, Cilium Tetragon) are specifically designed to observe and analyze container and host behavior during execution. They can detect and alert on anomalous activities like unauthorized process execution, file system changes, or suspicious system calls, directly addressing the need for real-time threat detection within the cluster.

Why the other options are wrong

  • A. SAST tools analyze source code for vulnerabilities before runtime and do not monitor live container behavior.
  • C. Image vulnerability scanners identify known vulnerabilities in container images during the build or registry phase, not during runtime execution.
  • D. NIDS monitors network traffic for suspicious patterns but does not provide visibility into internal container processes, file system changes, or system calls.

Runtime Security Monitoring

The continuous observation and analysis of container and host behavior during execution to detect and respond to security threats and policy violations in real-time.

  • Monitors process execution, file access, network activity, system calls.
  • Detects anomalies, policy violations, and known attack patterns.
  • Provides real-time alerts and can often enforce policies.

Memory trick: Runtime security watches your containers in action.

More Cloud Native Security questions