Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium

An incident response team is investigating a potential compromise where an attacker gained access to a container and is attempting to escalate privileges by exploiting vulnerabilities in the underlying host kernel. They suspect the attacker is trying to break out of the container's isolation. Which Linux kernel mechanism provides the fundamental isolation that prevents a process in one container from seeing or interacting with processes, network interfaces, or filesystems of the host or other containers by default?

  1. ALinux Namespaces
  2. BSeccomp (Secure Computing mode)
  3. Ccgroups (Control Groups)
  4. DAppArmor
Show answer & explanation

Correct answer: A. Linux Namespaces

Linux Namespaces provide the fundamental isolation for containers by isolating system resources like process IDs (PID), network interfaces, mount points, and user IDs. This prevents a process in one namespace (container) from seeing or affecting resources in another.

Why the other options are wrong

  • B. Seccomp restricts system calls a process can make, which is a security layer on top of namespaces, not the fundamental isolation mechanism itself.
  • C. cgroups limit resource usage (CPU, memory) but do not provide isolation of system views.
  • D. AppArmor is a Mandatory Access Control (MAC) system for broader policy enforcement, complementing namespaces but not providing the initial isolation.

Linux Namespaces

A Linux kernel feature that partitions global system resources (like process IDs, network interfaces, and mount points) so that processes within a namespace see an isolated instance of that resource.

  • Provides fundamental container isolation.
  • Creates isolated 'views' of system resources.
  • Key types: PID, NET, MNT, UTS, IPC, USER.

Memory trick: Namespaces carve out isolated views for containers.

More Cloud Native Security questions