Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityEasy
A security operations team wants to implement a strategy to detect and respond to suspicious activities and potential threats *within* running containers and on Kubernetes nodes. This includes monitoring for unauthorized process execution, file integrity changes, and network anomalies that might indicate a compromise. Which cloud-native security approach is specifically designed to address these concerns?
- AImage Scanning
- BSecrets Management
- CSupply Chain Security
- DRuntime Security Monitoring
Show answer & explanationAnswer & explanation
Correct answer: D. Runtime Security Monitoring
Runtime Security Monitoring focuses on observing and analyzing the behavior of applications and infrastructure during execution to detect and respond to threats in real-time, such as unauthorized processes, file changes, or suspicious network activity.
Why the other options are wrong
- A. Image Scanning identifies vulnerabilities in container images *before* they run, not during runtime.
- B. Secrets Management protects sensitive data like credentials, not monitoring active threats.
- C. Supply Chain Security focuses on securing the software development and delivery process, not runtime execution.
Runtime Security Monitoring
The continuous observation and analysis of running systems, applications, and infrastructure to detect and respond to security threats, anomalous behavior, and compliance violations in real-time.
- Detects threats during execution.
- Monitors processes, file changes, network activity.
- Crucial for identifying active compromises.
- Complements 'shift-left' and pre-runtime security.
Memory trick: Runtime monitoring watches for active threats.