Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard
An incident response team discovers that a compromised container in their Kubernetes cluster has managed to perform actions outside its intended scope, potentially affecting other containers on the same node. The team wants to understand how the container was initially isolated and what mechanisms could have prevented this lateral movement. Which Linux kernel feature is primarily responsible for isolating processes and resources (like filesystems, network interfaces, and process IDs) between containers?
- ASELinux
- BLinux Namespaces
- CControl Groups (cgroups)
- DAppArmor
Show answer & explanationAnswer & explanation
Correct answer: B. Linux Namespaces
Linux Namespaces are the fundamental kernel technology that provides process and resource isolation for containers. By giving each container its own view of system resources (like process IDs, network interfaces, mount points, and user IDs), namespaces prevent processes in one container from seeing or interacting with resources in other containers or the host system, thereby limiting lateral movement.
Why the other options are wrong
- A. SELinux is a Mandatory Access Control (MAC) system that enforces fine-grained access policies based on security labels, but it builds upon the isolation provided by namespaces rather than being the primary isolation mechanism itself.
- C. Control Groups (cgroups) manage and limit resource usage (CPU, memory, I/O) for processes, but they do not provide isolation of what processes can *see* or *interact* with.
- D. AppArmor is another MAC system that restricts what programs can do (e.g., file access, network access), similar to SELinux, and also relies on namespaces for fundamental isolation.
Linux Namespaces
A Linux kernel feature that partitions kernel resources such that one set of processes sees one set of resources, while another set of processes sees a different set. This provides the fundamental isolation for containers.
- Isolates process IDs, network interfaces, mount points, user IDs, etc.
- Each container gets its own isolated view of system resources.
- Crucial for preventing containers from interfering with each other or the host.
Memory trick: Namespaces grant each container its own isolated world.