Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard
An incident response team is investigating a potential compromise. They suspect an attacker might have gained access to a container and is attempting to move laterally within the cluster by exploiting a vulnerability that allows them to interact with the underlying host kernel. Which Linux kernel feature is designed to restrict the system calls a process can make, thereby mitigating such privilege escalation attempts?
- ASeccomp
- BAppArmor
- CCgroups
- DNamespaces
Show answer & explanationAnswer & explanation
Correct answer: A. Seccomp
Seccomp (Secure Computing mode) is a Linux kernel feature that allows a process to restrict the system calls it can make. By filtering syscalls, seccomp can prevent a compromised container from performing actions that could lead to privilege escalation or host compromise, even if other protections fail.
Why the other options are wrong
- B. AppArmor is a Linux security module that restricts program capabilities (file access, network access) based on profiles, but seccomp specifically focuses on syscall filtering.
- C. Cgroups (Control Groups) manage and limit resource allocation (CPU, memory) for processes, not syscalls.
- D. Namespaces provide isolation for various system resources (PID, network, filesystem) but do not restrict syscalls directly.
Seccomp (Secure Computing mode)
A Linux kernel feature that allows a process to restrict the set of system calls it can make, thereby reducing the attack surface and mitigating privilege escalation vulnerabilities in containers.
- Filters system calls a process can execute.
- Can be configured with profiles (whitelist/blacklist).
- Enhances container isolation against kernel exploits.
Memory trick: Namespaces isolate, Cgroups limit, Seccomp restricts syscalls, AppArmor profiles behavior.