
EC-CouncilNetwork Defense Essentials
Domain 4Objective 2
Containerization Technologies and Security Challenges NDE Practice Questions (Page 9)
Part of the Virtualization and Cloud Computing Security domain, which makes up ~12% of our current practice bank.
54questions here
11free pages
10concepts
Questions 41–45
- 41
A security team is investigating a breach where an attacker gained access to a container and then moved laterally to other containers on the same host. The attacker exploited a misconfigured container that had the CAP_SYS_ADMIN capability and was running in privileged mode. Which preventive measure would have MOST LIKELY stopped this attack?
Select an answer first - 42
A company runs a containerized application in a Kubernetes cluster. They need to ensure that only the frontend pods can communicate with the backend pods, and that traffic between pods is encrypted. They also want to avoid the overhead of a service mesh. Which approach best meets these requirements?
Select an answer first - 43
What is the primary purpose of a container registry?
Select an answer first - 44
A company is migrating from Docker Swarm to Kubernetes. They have a legacy application that relies on Docker Swarm's built-in load balancing and service discovery. During the migration, they need to maintain the same level of network security and observability. Which Kubernetes features should they use to replace these Swarm capabilities?
Select an answer first - 45
A security operations team wants to detect anomalous network traffic between containers in a Kubernetes cluster. Which approach should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.