Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard

An incident response team is investigating a potential compromise. They suspect an attacker might have gained access to a container and is attempting to move laterally within the cluster by exploiting a vulnerability that allows them to interact with the underlying host kernel. Which Linux kernel feature is designed to restrict the system calls a process can make, thereby mitigating such privilege escalation attempts?

  1. ASeccomp
  2. BAppArmor
  3. CCgroups
  4. DNamespaces
Show answer & explanation

Correct answer: A. Seccomp

Seccomp (Secure Computing mode) is a Linux kernel feature that allows a process to restrict the system calls it can make. By filtering syscalls, seccomp can prevent a compromised container from performing actions that could lead to privilege escalation or host compromise, even if other protections fail.

Why the other options are wrong

  • B. AppArmor is a Linux security module that restricts program capabilities (file access, network access) based on profiles, but seccomp specifically focuses on syscall filtering.
  • C. Cgroups (Control Groups) manage and limit resource allocation (CPU, memory) for processes, not syscalls.
  • D. Namespaces provide isolation for various system resources (PID, network, filesystem) but do not restrict syscalls directly.

Seccomp (Secure Computing mode)

A Linux kernel feature that allows a process to restrict the set of system calls it can make, thereby reducing the attack surface and mitigating privilege escalation vulnerabilities in containers.

  • Filters system calls a process can execute.
  • Can be configured with profiles (whitelist/blacklist).
  • Enhances container isolation against kernel exploits.

Memory trick: Namespaces isolate, Cgroups limit, Seccomp restricts syscalls, AppArmor profiles behavior.

More Cloud Native Security questions