フリー問題

Kubernetes and Cloud Native Security Associate のフリー問題 1 / 20 問目

問題文

A security review finds that a cluster runs on virtual machines in a public cloud account where several teams share administrative credentials. The Pods themselves run as non-root with a restricted security context. Under the 4Cs model, where does the most significant residual risk sit, and why?

選択肢

  1. At the Cloud layer, because anyone holding administrative credentials for the account can reach the nodes directly and bypass the controls configured inside the cluster.
  2. At the Code layer, because a restricted security context does not prevent the application from containing a defect that an attacker could use to obtain arbitrary execution inside the container.
  3. At the Container layer, because a restricted security context still permits the container to resolve names through the cluster DNS service and then reach other Pods.
  4. At the Cluster layer, because the restricted security context is applied per Pod rather than per namespace, and the namespace is left with no guarantee.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。