Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium
A containerized application experiences a security incident where a malicious process attempts to modify the root filesystem. The security team wants to ensure that, by default, all containers run with a read-only root filesystem to prevent such tampering. Which setting in the Pod's securityContext should be configured to achieve this?
- Aprivileged: false
- BallowPrivilegeEscalation: false
- CreadOnlyRootFilesystem: true
- DrunAsNonRoot: true
Show answer & explanationAnswer & explanation
Correct answer: C. readOnlyRootFilesystem: true
Setting `readOnlyRootFilesystem: true` in a container's securityContext (or Pod's, which applies to all containers) makes the container's root filesystem read-only, effectively preventing any malicious process from writing to or modifying system files.
Why the other options are wrong
- A. `privileged: false` prevents the container from running in privileged mode, which grants extensive host capabilities, but doesn't directly control root filesystem write access for non-privileged containers.
- B. `allowPrivilegeEscalation: false` prevents a process from gaining more privileges than its parent, but doesn't make the filesystem read-only.
- D. `runAsNonRoot: true` ensures the container runs as a non-root user, which is a good practice but doesn't explicitly make the root filesystem read-only.
Pod SecurityContext
A field in a Pod or Container specification that defines privilege and access control settings for a Pod or Container, such as user ID, group ID, and capabilities.
- Applies security settings at Pod or Container level.
- Controls user/group IDs, filesystem permissions, capabilities.
- Helps enforce least privilege and isolation.
Memory trick: SecurityContext is the container's rulebook for how it can run.