Docker Security
Docker Security
Beginner
Q1: What is Docker security?
Docker security is the set of practices, controls, and configurations used to protect containers, images, hosts, and the workloads they run.
Q2: Why is Docker security important?
Containers can expose vulnerabilities, secrets, and attack surfaces if they are not carefully designed and managed.
Q3: What is a container escape?
A container escape is a vulnerability or misconfiguration that allows an attacker to break out of the container isolation boundary.
Q4: Why is container isolation important?
It prevents a compromised container from affecting the host or other containers.
Q5: What is the host kernel?
The host kernel is the Linux kernel running on the Docker host, shared by containers in many setups.
Q6: What is a container attack surface?
The container attack surface is the set of things an attacker could exploit, such as exposed ports, running processes, network access, and filesystems.
Q7: What is a Docker image?
A Docker image is a read-only filesystem snapshot used as the basis for running containers.
Q8: Why are image vulnerabilities important?
Because vulnerable base images and application dependencies can be exploited once a container is running.
Q9: What is a vulnerable dependency?
A vulnerable dependency is a library, package, or binary that contains a known security flaw.
Q10: What is a CVE?
A CVE (Common Vulnerabilities and Exposures) is a publicly known software vulnerability.
Q11: What is a security scan?
A security scan inspects container images, filesystems, and packages for known vulnerabilities.
Q12: What is Trivy?
Trivy is a common image scanner used to detect vulnerabilities in container images and filesystems.
Q13: What is Anchore?
Anchore is a container image scanning and policy engine used for security validation.
Q14: Why scan Docker images?
Because vulnerable base images and packages can become the entry point for container compromise.
Q15: What is a minimal image?
A minimal image contains only the runtime dependencies necessary to run the application.
Q16: Why do minimal images help security?
They reduce the number of packages and libraries an attacker can exploit.
Q17: What is a distroless image?
A distroless image contains only runtime artifacts and not a shell, package manager, or other developer tools.
Q18: Why remove shell binaries from containers?
Because shells can make privilege escalation and post-exploitation easier for attackers.
Q19: What is the root user?
The root user has full privileges on the system and can perform almost any action.
Q20: Why should containers avoid running as root?
Because a compromised process running as root can access the full container filesystem and potentially more.
Q21: What is a non-root user?
A non-root user has restricted privileges and reduces the blast radius of compromise.
Q22: What is a Docker USER instruction?
The USER instruction sets the user that will run commands in the container.
Q23: What is a security best practice for Dockerfiles?
Prefer small, minimal, patched images and avoid running as root whenever possible.
Q24: What is a public Docker image risk?
Public images may contain malicious content or outdated, vulnerable software if not curated.
Q25: Why use trusted base images?
Trusted base images are often patched, maintained, and verified more regularly.
Q26: What is a private registry?
A private registry hosts images inside an internal network or organization-controlled environment.
Q27: What is a public registry?
A public registry hosts images publicly, such as Docker Hub.
Q28: What is image provenance?
Image provenance is the record of where the image came from, how it was built, and whether it is trusted.
Q29: What is image signing?
Image signing allows a system to verify the authenticity and integrity of a container image.
Q30: What is Cosign?
Cosign is a tool for signing and verifying container images using cryptographic signatures.
Q31: What is Sigstore?
Sigstore is a project used to sign, verify, and store software artifact signatures securely.
Q32: What is a registry scan?
A registry scan checks images pushed into a registry for vulnerabilities and policy violations.
Q33: What is a Docker daemon?
The Docker daemon is the service that manages container runtime and image operations on the host.
Q34: Why are Docker daemon privileges sensitive?
Because a compromised daemon can issue malicious container commands and affect the host.
Q35: What is Docker socket?
The Docker socket is the Unix socket used by Docker clients to talk to the Docker daemon.
Q36: Why is the Docker socket risky?
If exposed or misused, it can allow control of the host or other containers.
Q37: What does container escape via Docker socket mean?
A process inside a container could potentially use the Docker socket to manage other containers or the host if misconfigured.
Q38: What is the Docker socket mount?
It is a bind mount of the Docker socket into a container, often used in CI/CD or dev tools but risky.
Q39: Why is mounting the Docker socket dangerous?
Because it effectively gives the container privileged access to Docker daemon operations.
Q40: What is a rootless container?
A rootless container runs without requiring root privileges in the host namespace.
Q41: What is the security benefit of rootless mode?
It reduces the risk of host-level privilege escalation if the container is compromised.
Q42: What is Linux namespaces?
Namespaces isolate container processes, networks, mounts, and users from the host OS.
Q43: What is cgroups?
cgroups limit CPU, memory, and process usage for containers.
Q44: Why are cgroups important for security?
They prevent a compromised app from consuming all host resources and causing denial-of-service.
Q45: What is seccomp?
Seccomp is a Linux kernel security feature that restricts the system calls a process can make.
Q46: Why does seccomp matter?
It reduces the system-call surface available to a compromised container.
Q47: What is AppArmor?
AppArmor is a Linux Mandatory Access Control (MAC) system that restricts what applications can do.
Q48: What is SELinux?
SELinux is another MAC system commonly used to enforce containment and policy.
Q49: What is the difference between namespaces and cgroups?
Namespaces isolate visibility; cgroups limit resource use.
Q50: What is network isolation?
Network isolation prevents containers from accessing or reaching unwanted networks or services.
Q51: What is Docker bridge network security?
Bridge networks isolate containers on the same host, but they still require firewall or policy rules for strict segmentation.
Q52: Why do containers use network policies?
Network policies restrict traffic between workloads, reducing unintended lateral movement.
Q53: What is a microservice security boundary?
A microservice security boundary is the point where one service is isolated from another by network or policy boundaries.
Q54: What is a Docker secret?
A Docker secret is a secure mechanism to inject sensitive data such as passwords or TLS keys into services in a controlled way.
Q55: Why use Docker secrets instead of environment variables?
Environment variables can leak in logs, process lists, or debugging tools, while secrets are handled more securely.
Q56: What are container secrets?
Container secrets are sensitive values stored as files or secret objects and injected at runtime.
Q57: What are environment variables?
Environment variables are values passed to a process, but they may be exposed in process inspection and logs.
Q58: Why avoid secrets in image layers?
Image layers are stored in the image filesystem and can be inspected or extracted later.
Q59: What is a compromised image?
A compromised image includes malicious code, backdoors, or unsafe configuration.
Q60: What is a trusted image pipeline?
A trusted image pipeline includes scanning, signing, and validation before the image reaches production.
Q61: What is a Docker registry vulnerability?
A registry vulnerability may let malicious images or tampered content get published or pulled.
Q62: Why use private registries?
Private registries give you control over who can pull and push images and how they are scanned.
Q63: What is Docker content trust?
Docker Content Trust verifies signed images before the client pulls them.
Q64: What is image tag trust?
Image tag trust means trusting the image tag and associated signature, not just the name.
Q65: What is a malicious Dockerfile?
A malicious Dockerfile may add scripts or dependencies that perform unauthorized actions at build or run time.
Q66: Why should build contexts be restricted?
The Docker build context may expose local secrets or files that get embedded into the image if not filtered with .dockerignore.
Q67: What is .dockerignore?
.dockerignore excludes files from the Docker build context to avoid leaking secrets or large directories.
Q68: Why is .dockerignore security-sensitive?
Because leaked files may be placed into the image or build cache.
Q69: What is a runtime secret file?
A runtime secret file is mounted into the container for sensitive information such as TLS private keys.
Q70: Why mount secrets as files?
Some workloads, like TLS, expect files rather than environment variables.
Q71: What is a Docker health check?
A health check asks whether a container is alive and working properly.
Q72: Why is health checking relevant to security?
Healthy services are less likely to be compromised or in a failed state, and health checks can reduce accidental exposure of broken systems.
Q73: What is Docker logging?
Docker logs capture container output, which may include secrets if mishandled.
Q74: Why avoid logging sensitive data?
Because logs may be accessible to operators or centralized monitoring systems beyond the container.
Q75: What is a container debugging risk?
Debugging containers often requires shell access, which can increase risk if the container is not hardened.
Q76: Why restrict exec into containers?
Because shell access can help an attacker inspect and manipulate files, secrets, and system state.
Q77: What is the principle of least privilege?
The principle of least privilege means giving only the minimum permissions needed for a task.
Q78: Why is least privilege important in Docker?
It reduces the ability of a compromised container or service to do damage.
Q79: What is container resource limits?
Resource limits constrain CPU, memory, and PIDs to reduce abuse and denial-of-service opportunities.
Q80: What is a Docker memory limit?
A memory limit restricts how much RAM a container can consume.
Q81: What is a CPU limit?
A CPU limit prevents a container from monopolizing host CPU resources.
Q82: What is a PID limit?
A PID limit restricts how many processes a container can create.
Q83: Why limit resources?
Resource limits reduce the impact of runaway or malicious workloads.
Q84: What is docker run –cap-drop?
--cap-drop removes Linux capabilities from a container to reduce privilege.
Q85: What are Linux capabilities?
Capabilities are fine-grained privileges beyond the traditional root/non-root split.
Q86: Why drop capabilities?
Because a container may need fewer privileges than a full root process.
Q87: What is seccomp profile?
A seccomp profile restricts which system calls are allowed.
Q88: What is AppArmor profile?
An AppArmor profile restricts a container to an allowed set of file operations and capabilities.
Q89: What is a read-only root filesystem?
A read-only root filesystem prevents tampering with the container’s filesystem and helps enforce integrity.
Q90: Why use read-only filesystem?
It reduces the chance of malicious writes and makes the filesystem more predictable.
Q91: What is a tmpfs mount?
A tmpfs mount keeps temporary data in memory, reducing writes to disk and making state more ephemeral.
Q92: What is a Docker kill signal?
A signal sent to a container can terminate processes and affect containers if an attacker can send or abuse them.
Q93: What is a user namespace?
A user namespace maps host UIDs to container UIDs and can reduce privilege escalation risk.
Q94: What is a privileged container?
A privileged container runs with extra Linux capabilities and has broad access to the host and devices.
Q95: Why avoid privileged mode?
Because it weakens isolation and gives the container near-host capabilities.
Q96: What is Docker CapAdd?
--cap-add adds Linux capabilities to a container and should be used sparingly.
Q97: What is a container breakout?
A breakout is the exploitation of a vulnerability to escape the containment boundary.
Q98: What is a host compromise?
A host compromise occurs when an attacker gains access to the underlying Docker host.
Q99: What is a lateral movement risk?
Lateral movement is when a compromised container is used to access other containers or host systems.
Q100: What is the difference between safe and unsafe Docker networking?
Unsafe Docker networking exposes more services and routes than necessary; safe networks enforce segmentation and firewalling.
Intermediate
Q101: What is Docker network segmentation?
It means separating container workloads into distinct networks and trust zones.
Q102: Why is network segmentation important?
It reduces the chance that a compromised container can reach unrelated services.
Q103: What is a Docker bridge network?
A Docker bridge network is a default internal network for containers on the same host.
Q104: Why should not all containers share the same bridge?
Because a compromised container on the same network may discover or attack others.
Q105: What is a user-defined network?
A user-defined network allows better naming, DNS, and isolation than the default bridge.
Q106: Why use custom networks?
They help enforce traffic boundaries and manage service discovery more intentionally.
Q107: What is a container firewall?
A firewall restricts which network ports or destinations a container may use.
Q108: What is iptables with Docker?
Docker uses iptables rules to implement port publishing and firewalling.
Q109: Why is firewall configuration important?
Without it, attackers may probe or reach unintended ports from other containers or external networks.
Q110: What is a Docker security group concept?
It is an abstraction in some environments that acts like a firewall policy for container traffic.
Q111: What is a Docker engine security concern?
The daemon, privileges, and host environment are among the highest-risk parts of the Docker stack.
Q112: Why patch Docker regularly?
Because vulnerabilities in the engine, runtime, or kernel can affect the host.
Q113: What is host hardening?
Host hardening includes patching, disabling unnecessary services, setting secure kernel settings, and limiting access.
Q114: What is a Docker user namespace?
It remaps container root to an unprivileged user on the host, reducing the privilege of the container.
Q115: What is a rootless Docker installation?
Rootless Docker avoids root on the host by running the daemon and containers as a non-root user.
Q116: Why use rootless mode?
It reduces the impact of a compromised runtime process.
Q117: What is the security concern of Docker Compose?
Compose can be used to run many containers with broad network access and sharing if not designed carefully.
Q118: What is a Docker threat model?
A threat model identifies who may attack the system, how they might do so, and what controls reduce the risk.
Q119: Why is threat modeling useful?
It forces engineers to think systematically about privilege boundaries and threat paths.
Q120: What is dependency vulnerability scanning?
It detects vulnerable libraries, packages, or OS-level dependencies in images.
Q121: What is a package manager in the final image?
A package manager, such as apt or apk, increases the set of tools an attacker could use if the container is compromised.
Q122: Why remove apt/apk caches?
Because they can make the image larger and may contain metadata or installed packages not needed by the app.
Q123: What is a multi-stage Docker build for security?
A multi-stage build can build the app in one stage and ship only the runtime artifact in a separate stage.
Q124: Why do multi-stage builds help security?
They reduce final image size and can eliminate compilers and package managers from the production image.
Q125: What is image signing policy?
A signing policy defines which images are trusted, who can sign them, and under which conditions.
Q126: What is a registry admission policy?
It controls what images can be pushed or pulled based on scan results, signatures, or tags.
Q127: Why is admission control useful?
It prevents insecure or untrusted images from entering a cluster or deployment workflow.
Q128: What is a container policy engine?
A policy engine evaluates images or runtime manifests against security rules before deployment.
Q129: What is a security baseline?
A security baseline is a set of minimum controls, such as no root, no privileged mode, scan passes, and signed images.
Q130: What is a "no root" policy?
It requires containers to run as non-root users whenever possible.
Q131: What is "read-only root filesystem" policy?
It enforces a writable layer only for needed runtime state, reducing mutable attack surface.
Q132: What is "no new privileged capabilities" policy?
It forbids containers from requesting extra Linux capabilities beyond the minimum required.
Q133: What is image provenance enforcement?
It ensures images originate from approved registries, builds, or signing identities.
Q134: Why use a restricted registry mirror?
It reduces the chance of pulling malicious or outdated images from untrusted public registries.
Q135: What is a Docker configuration drift?
Configuration drift is when the security settings of containers or hosts diverge from approved standards over time.
Q136: What is a hardened Docker baseline?
A hardened baseline includes patched OS, minimum privileges, network restrictions, and limited external exposure.
Q137: Why is runtime monitoring important?
It helps detect suspicious processes, unauthorized network connections, and unexpected privilege changes.
Q138: What is docker events?
Docker events report lifecycle changes to containers, images, and networks.
Q139: What is container-level forensics?
It is the process of investigating a container compromise by looking at filesystem, logs, network, and process state.
Q140: What is a malicious container image inside a registry?
It is a tampered or malicious image stored in a registry and pulled by a system without validation.
Q141: What is a secret in an image layer?
A secret placed in an image layer may be recoverable by anyone with access to the image.
Q142: Why avoid embedding TLS keys in images?
Because they become part of the image history and may be copied into many environments.
Q143: Why avoid storing credentials in Dockerfile?
Because they are embedded in image layers and viewable through image history.
Q144: How should secrets be supplied to containers?
Use Docker secrets, mounted volumes, or a secret manager with controlled access.
Q145: What is a Dockerfile best practice to reduce secret leakage?
Use build arguments carefully and never bake secrets directly into the final image unless absolutely required.
Q146: What is "builder stage should not ship secrets"?
The build stage can use secrets during compilation, but they should not remain in the final image.
Q147: Why are package manager caches sensitive?
They may include metadata and dependencies from internal registries or secret-laden build layers.
Q148: Why is shell history relevant?
A shell in the container may retain commands and secrets if used in debugging or build processes.
Q149: What is a malicious dependency injection?
An attacker can influence dependency resolution or package installation steps to add malicious code.
Q150: What is a reproducible build?
A reproducible build gives the same output for the same source and environment, reducing attack vectors from nondeterministic builds.
Q151: What is a vulnerability feed?
A vulnerability feed is the database or service that provides known issues and patch information.
Q152: What is a CVE scanning policy?
It may block images with critical or high vulnerabilities before deployment.
Q153: What is a security gate in CI/CD?
A security gate checks the image or artifact before it is allowed to proceed to deployment.
Q154: What is a Docker compliance policy?
It defines security expectations such as scan results, signed images, and runtime constraints.
Q155: Why monitor for suspicious outbound traffic from containers?
Because compromised containers often call home or exfiltrate data to an attacker-controlled endpoint.
Q156: Why restrict egress traffic?
It limits the damage a compromised container can do externally.
Q157: What is egress control?
Egress control restricts outbound network connections from containers.
Q158: Why is egress filtering important?
It protects against malware beaconing, data exfiltration, and command-and-control traffic.
Q159: What is container break-out prevention?
It includes kernel hardening, seccomp, AppArmor, namespaces, user namespaces, and minimal privileges.
Q160: What is kernel hardening?
Kernel hardening reduces known vulnerabilities and increases the difficulty of exploitation.
Q161: What is unprivileged container mode?
It ensures containers do not run with host-root-like privileges or capabilities.
Q162: Why is Docker daemon security critical?
Because if the daemon is compromised, the entire host is at risk.
Q163: What is host-level isolation for Docker?
It includes separate hosts, VMs, or hypervisors for workloads with different trust levels.
Q164: What is a trusted execution boundary?
It is a level of isolation that prevents unauthorized access across workload boundaries.
Q165: What is a dedicated host for sensitive workloads?
It isolates high-risk or high-value systems away from other containers or services.
Q166: How does Docker security differ from VM security?
VMs provide stronger isolation at the hypervisor layer; Docker containers rely more on kernel and process isolation.
Q167: Why do some organizations use VM-based isolation for critical containers?
To reduce the risk of cross-container or host compromise when high security is required.
Q168: What is Docker daemon socket protection?
It means restricting access to the Docker socket to only trusted users or automation agents.
Q169: Why is mandatory access control helpful?
It enforces policy beyond simple file permissions and reduces the chance of privilege abuse.
Q170: What is process isolation?
Process isolation means one container’s processes are not directly visible to others.
Q171: What is file system isolation?
Filesystem isolation keeps each container’s file system separate from the host and other containers.
Q172: What is user-level networking policy?
It limits which destinations a container can reach over the network.
Q173: What is the relationship between Docker security and observability?
Good observability helps detect suspicious activity, abnormal process launch, or unexpected network access.
Q174: What is Docker audit logging?
It logs actions performed by the Docker daemon and system administrators.
Q175: Why are audit logs useful?
They help reconstruct what happened during a security incident or policy violation.
Q176: What is a service account in Docker?
A service account or service identity is used to grant controlled access to registries or secret stores.
Q177: What is RBAC for Docker registries?
RBAC (Role-Based Access Control) restricts registry access by role and identity.
Q178: What is image provenance after build?
It is the chain showing where the image came from, who built it, and whether it was signed.
Q179: What is signing validation before deployment?
It ensures the image signature matches a trusted identity before it can be deployed.
Q180: Why are artifactory or registry policy checks important?
They prevent untrusted or outdated images from being used in production.
Advanced / Expert
Q181: What is Kubernetes pod security policy?
A pod security policy imposes security constraints on workloads, often relevant when Docker is part of a Kubernetes deployment.
Q182: What is security context in Kubernetes?
A security context configures user ID, capabilities, seccomp, and privilege settings for containers.
Q183: Why is Docker security tied to the host kernel?
Because many container security boundaries ultimately depend on kernel features such as namespaces, seccomp, and cgroups.
Q184: What is a kernel exploit?
A kernel exploit can allow attackers to escape container isolation and access host-level resources.
Q185: Why is patching the host crucial?
Because a kernel vulnerability may undermine all container isolation.
Q186: What is a container breakout via kernel bug?
It is an exploit that takes advantage of a kernel defect to escape the container and reach the host.
Q187: What is seccomp bypass?
A seccomp bypass is a method to evade Linux seccomp restrictions and perform disallowed actions.
Q188: What is AppArmor bypass?
An AppArmor bypass is a policy evasion that allows behavior beyond the intended confinement.
Q189: Why do advanced Docker security setups use multiple controls?
Because single controls alone are not enough; defense-in-depth is essential.
Q190: What is defense-in-depth?
Defense-in-depth uses multiple layers of protection, such as image scanning, privileged restrictions, network segmentation, and runtime monitoring.
Q191: What is runtime threat detection?
Runtime threat detection looks for suspicious process execution, malformed network traffic, or unexpected file changes.
Q192: What is eBPF security monitoring?
eBPF can inspect system calls, network behavior, and process activity with low overhead for security monitoring.
Q193: What is container forensics?
Container forensics analyzes the container filesystem, process list, logs, and network artifacts after an incident.
Q194: What is static analysis of Dockerfiles?
Static analysis checks Dockerfile instructions for risky patterns such as insecure base images or unrestricted privileges.
Q195: What is image lifecycle security?
It includes build, scan, sign, promote, deploy, and retire stages, each with security controls.
Q196: What is artifact promotion security?
It ensures only scanned, signed, and compliant images move from dev to staging to production.
Q197: Why are container registry policies important?
Because registries are often the single point where malicious or policy-violating images can be introduced.
Q198: What is attacker persistence in containers?
Attackers may leave malicious binaries, cron jobs, or scripts in a compromised container to persist beyond the immediate session.
Q199: What is a dangerous container configuration?
Examples include privileged mode, host networking, Docker socket mounts, and broad host port exposure.
Q200: What is the main lesson in Docker security?
Docker security is not just about the container runtime; it spans image provenance, privilege boundaries, network isolation, secrets handling, registry policy, and host hardening.