Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Linux Foundation KCSA Exam - Topic 5 Question 17 Discussion

A container running in a Kubernetes cluster has permission to modify host processes on the underlying node.What combination of privileges and capabilities is most likely to have led to this privilege escalation?
A) There is no combination of privileges and capabilities that permits this.
B) hostPID and SYS_PTRACE
C) hostPath and AUDIT_WRITE
D) hostNetwork and NET_RAW

Linux Foundation KCSA Exam - Topic 5 Question 17 Discussion

Actual exam question for Linux Foundation's KCSA exam
Question #: 17
Topic #: 5
[All KCSA Questions]

A container running in a Kubernetes cluster has permission to modify host processes on the underlying node.

What combination of privileges and capabilities is most likely to have led to this privilege escalation?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Georgene
1 day ago
Right, it’s more about logging than modifying.
upvoted 0 times
...
Beckie
6 days ago
C seems less likely. AUDIT_WRITE doesn't modify processes.
upvoted 0 times
...
Britt
11 days ago
True, but I wonder if C could be a possibility too.
upvoted 0 times
...
Georgene
17 days ago
Exactly! SYS_PTRACE is powerful for debugging.
upvoted 0 times
...
Beckie
22 days ago
I doubt it. The capabilities are there for a reason.
upvoted 0 times
...
Britt
27 days ago
But what about A? Could there really be no combination?
upvoted 0 times
...
Georgene
1 month ago
I agree, B makes sense. hostPID allows access to host processes.
upvoted 0 times
...
Beckie
1 month ago
This question is tricky. I think B is the right answer.
upvoted 0 times
...
Tiera
1 month ago
Isn't it risky to give those permissions in the first place?
upvoted 0 times
...
Shala
2 months ago
C is a stretch, not sure it fits the scenario.
upvoted 0 times
...
Iluminada
2 months ago
Wow, I didn't know hostPID could do that!
upvoted 0 times
...
Jutta
2 months ago
I disagree, I think it's A. No way to modify host processes!
upvoted 0 times
...
King
2 months ago
B) hostPID and SYS_PTRACE seems right.
upvoted 0 times
...
Caitlin
2 months ago
I feel like hostNetwork and NET_RAW are more about network capabilities. They don’t seem to relate to modifying host processes.
upvoted 0 times
...
Jade
2 months ago
I don’t recall hostPath being related to modifying processes directly. I thought it was more about file system access.
upvoted 0 times
...
Sophia
3 months ago
I’m not entirely sure, but I think SYS_PTRACE might be involved in modifying processes. It sounds familiar from our practice questions.
upvoted 0 times
...
Mee
3 months ago
I remember reading that hostPID allows a container to see and interact with processes on the host, which could lead to privilege escalation.
upvoted 0 times
...

Save Cancel