CV0-004 · Question #219
A security engineer Identifies a vulnerability m a containerized application. The vulnerability can be exploited by a privileged process to read tie content of the host's memory. The security engineer
Sign in or unlock CV0-004 to reveal the answer and full explanation for question #219. The question stem and answer options stay visible for context.
Question
A security engineer Identifies a vulnerability m a containerized application. The vulnerability can be exploited by a privileged process to read tie content of the host's memory. The security engineer reviews the following Dockerfile to determine a solution to mitigate similar exploits:
Which of the following is the best solution to prevent similar exploits by privileged processes?
Exhibit
Options
- AAdding the USER myappuserinstruction
- BPatching the host running the Docker daemon
- CChanging FROM alpiner3.17 to FROM alpine:latest
- DRunning the container with the ready-only filesystem configuration
Unlock CV0-004 to see the answer
You've previewed enough free CV0-004 questions. Unlock CV0-004 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
