nerdexam
CompTIA

CV0-004 · Question #219

A security engineer Identifies a vulnerability m a containerized application. The vulnerability can be exploited by a privileged process to read tie content of the host's memory. The security engineer

Sign in or unlock CV0-004 to reveal the answer and full explanation for question #219. The question stem and answer options stay visible for context.

Security

Question

A security engineer Identifies a vulnerability m a containerized application. The vulnerability can be exploited by a privileged process to read tie content of the host's memory. The security engineer reviews the following Dockerfile to determine a solution to mitigate similar exploits:

Which of the following is the best solution to prevent similar exploits by privileged processes?

Exhibit

CV0-004 question #219 exhibit

Options

  • AAdding the USER myappuserinstruction
  • BPatching the host running the Docker daemon
  • CChanging FROM alpiner3.17 to FROM alpine:latest
  • DRunning the container with the ready-only filesystem configuration

Unlock CV0-004 to see the answer

You've previewed enough free CV0-004 questions. Unlock CV0-004 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Container Security#Dockerfile Security#Least Privilege#Vulnerability Mitigation
Full CV0-004 Practice