Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard

An incident response team is investigating a potential compromise where a malicious actor might have gained access to a Kubernetes node and tampered with the container runtime configuration, potentially enabling insecure features or backdoors. Which component of the Kubernetes security model is primarily responsible for ensuring the integrity and authenticity of the host's configuration and software, including the container runtime, from boot-up?

  1. AKubelet
  2. BKubernetes API Server
  3. CTrusted Platform Module (TPM) and Measured Boot
  4. DNetworkPolicy
Show answer & explanation

Correct answer: C. Trusted Platform Module (TPM) and Measured Boot

The Trusted Platform Module (TPM) combined with Measured Boot (or Secure Boot) provides a hardware-rooted chain of trust. This mechanism measures and cryptographically records the state of the boot components, including the firmware, bootloader, kernel, and often critical system binaries and configurations (like the container runtime), ensuring their integrity from the earliest boot stages.

Why the other options are wrong

  • A. Kubelet is the agent on the node; while it enforces pod configuration, it doesn't ensure the integrity of its own host or the container runtime from boot.
  • B. The API server is the control plane endpoint; it doesn't secure the underlying host configuration.
  • D. NetworkPolicy controls network traffic, not host integrity.

Trusted Platform Module (TPM)

A secure cryptoprocessor on a computer's motherboard that stores cryptographic keys and provides hardware-level security functions, often used for secure boot and measured boot.

  • Provides a hardware root of trust.
  • Used for secure boot, measured boot, and disk encryption.
  • Ensures integrity and authenticity of system components from boot.
  • Crucial for host-level security in cloud-native environments.

Memory trick: TPM measures your boot to ensure trust at the root.

More Cloud Native Security questions