Q: 5
[Emerging Technologies and Threats]
A security engineer wants to reduce the attack surface of a public-facing containerized application
Which of the following will best reduce the application's privilege escalation attack surface?
Options
Discussion
Its A, running containers as non-root limits privilege escalation. Pretty standard hardening step for Docker. Anyone see a catch here?
C or D here. Splitting remediation to separate containers (C) sounds like it'd limit compromise if one gets hit. Not totally sure if that blocks privilege escalation directly though. Anyone disagree?
A tbh, not super sure but looks like least privilege in Docker. Can someone confirm?
Be respectful. No spam.