Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard

A security incident response team discovers that a compromised container in their Kubernetes cluster exploited a vulnerability to gain root privileges on the host node. To mitigate this type of attack vector in the future, they want to implement a mechanism that isolates the container's processes and filesystem from the host more effectively, even if the container user is root. Which Linux kernel security feature, often leveraged by container runtimes, provides this enhanced isolation?

  1. Acgroups (control groups)
  2. Biptables
  3. CNamespaces
  4. DSELinux/AppArmor
Show answer & explanation

Correct answer: C. Namespaces

Linux Namespaces are a fundamental building block of container isolation. They partition kernel resources, allowing each container to have its own isolated view of processes (PID namespace), network interfaces (Net namespace), mount points (Mount namespace), users (User namespace), and more. This prevents a process inside one container from seeing or interacting with processes, filesystems, or networks of the host or other containers, even if running as root within its own namespace.

Why the other options are wrong

  • A. cgroups limit and monitor resource usage (CPU, memory), but do not provide process or filesystem isolation.
  • B. iptables manage network filtering and firewall rules, not process or filesystem isolation.
  • D. SELinux/AppArmor provide mandatory access control (MAC) and can further confine container processes, but Namespaces are the prerequisite for the basic isolation model.

Linux Namespaces

A Linux kernel feature that isolates and virtualizes system resources (like processes, network, mounts, users) for a group of processes, forming the foundation of containerization.

  • Each container gets its own isolated view of resources.
  • Key types: PID, Net, Mount, UTS, IPC, User.
  • Prevents processes in one namespace from affecting another.
  • Crucial for container security and multi-tenancy.

Memory trick: Namespaces make containers think they're alone.

More Cloud Native Security questions