Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium

A containerized application experiences a security incident where a malicious process attempts to modify the root filesystem. The security team wants to ensure that, by default, all containers run with a read-only root filesystem to prevent such tampering. Which setting in the Pod's securityContext should be configured to achieve this?

  1. Aprivileged: false
  2. BallowPrivilegeEscalation: false
  3. CreadOnlyRootFilesystem: true
  4. DrunAsNonRoot: true
Show answer & explanation

Correct answer: C. readOnlyRootFilesystem: true

Setting `readOnlyRootFilesystem: true` in a container's securityContext (or Pod's, which applies to all containers) makes the container's root filesystem read-only, effectively preventing any malicious process from writing to or modifying system files.

Why the other options are wrong

  • A. `privileged: false` prevents the container from running in privileged mode, which grants extensive host capabilities, but doesn't directly control root filesystem write access for non-privileged containers.
  • B. `allowPrivilegeEscalation: false` prevents a process from gaining more privileges than its parent, but doesn't make the filesystem read-only.
  • D. `runAsNonRoot: true` ensures the container runs as a non-root user, which is a good practice but doesn't explicitly make the root filesystem read-only.

Pod SecurityContext

A field in a Pod or Container specification that defines privilege and access control settings for a Pod or Container, such as user ID, group ID, and capabilities.

  • Applies security settings at Pod or Container level.
  • Controls user/group IDs, filesystem permissions, capabilities.
  • Helps enforce least privilege and isolation.

Memory trick: SecurityContext is the container's rulebook for how it can run.

More Cloud Native Security questions