Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard
A security team is investigating a potential compromise where an attacker gained access to a Kubernetes node and is attempting to extract sensitive data from Pods running on it. They want to ensure that even if an attacker gains control of a node, they cannot easily access the memory or processes of other Pods running on the same node. Which advanced isolation technology could provide an additional layer of defense by running Pods in lightweight virtual machines?
- AKata Containers or gVisor
- BContainerD runtime with default namespaces
- CNetworkPolicy isolation
- DSeccomp profiles
Show answer & explanationAnswer & explanation
Correct answer: A. Kata Containers or gVisor
Kata Containers and gVisor are examples of 'container runtimes' that enhance isolation by running containers within lightweight virtual machines or user-space kernels, respectively. This provides a stronger security boundary than traditional container isolation, making it much harder for an attacker on the host to escape into or compromise other Pods.
Why the other options are wrong
- B. ContainerD with default namespaces provides standard container isolation, which is what the question implies is insufficient against a compromised node.
- C. NetworkPolicy isolates network traffic, not processes or memory on the host.
- D. Seccomp profiles restrict system calls, which is a good practice but doesn't provide the same level of isolation against a compromised node as a VM-like boundary.
Hardware-enforced Isolation (e.g., Kata, gVisor)
Advanced container runtimes that provide stronger workload isolation by running containers inside lightweight virtual machines (Kata Containers) or user-space kernels (gVisor), mitigating risks from compromised host kernels or container escapes.
- Increases isolation beyond standard Linux namespaces and cgroups.
- Protects against kernel exploits and container escapes.
- Offers a stronger security boundary between containers and the host.
- Useful for multi-tenant environments or highly sensitive workloads.
Memory trick: Kata and gVisor virtualize for safety.