⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE [L2] Security Production Scenario [L2]

Q: During a pentest, the testers found they could exploit a vulnerability in your Node.js app to read `/etc/passwd`. What OS-level container configuration should standardly prevent this kind of filesystem roaming?

A fundamental tenant of container hardening is running the container with a Read-Only Root Filesystem.

#Security #Security #L2 #DevSecOps #Compliance #IAM
🎙️ Candidate Opening & Architectural Context
""When an interviewer asks how I respond to this security vulnerability, I emphasize immediate blast-radius containment. The interviewer is testing: Read-only root filesystems, container hardening.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Production Solution & Architecture

A fundamental tenant of container hardening is running the container with a Read-Only Root Filesystem. In Kubernetes, this is achieved by setting readOnlyRootFilesystem: true in the pod's securityContext. In Docker, it's the --read-only flag. When enabled, the application cannot overwrite binaries, modify /etc/passwd, or drop malicious payloads onto the disk during an exploit. Any directory the app legitimately needs to write to (like /tmp for caching) must be explicitly mounted as an ephemeral emptyDir or tmpfs volume, leaving the rest of the OS immutable and highly frustrating for attackers.

💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: A fundamental tenant of container hardening is running the container with a Read-Only Root Filesystem.."
⚡ 60-Second Elevator Pitch Talking Points
  • Immediate Triage: A fundamental tenant of container hardening is running the container with a Read-Only Root File
  • Run targeted verification commands before modifying configuration.
  • Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement
Want more Security scenarios?
Explore our complete collection of scenario-based Security interview runbooks.
Browse All Security Questions →

📚 Related Production Scenarios in Security