certslothcertsloth
KCSA/Topic 07

CNCF / Associate

Threat Modeling and Attack Paths

4 min read5 recall promptsReviewed 2026-10-10

Memory hook: Draw the boundary, follow the identity, then limit persistence and movement.

Must remember

A threat model explains what needs protection, who can attack it, how data and control cross boundaries, and which controls reduce risk. Start with a simple data-flow diagram: user to application; developer/CI to registry and API; API to etcd and nodes; workload to database, DNS, identity service and external endpoints. Identify trust changes at every crossing, including tenant-to-tenant and container-to-host boundaries.

Threat is a possible harmful event or actor; vulnerability is a weakness; risk combines likelihood and impact in context. A published CVE matters differently for an unreachable unused component and an exposed execution path. An attack surface includes endpoints, credentials, dependencies, configuration and people, not only public IP addresses.

Attack goal Kubernetes example Controls and evidence
Persistence An unauthorized CronJob, DaemonSet, controller or credential recreates access Restrict creation/grants, review controllers and audit configuration changes
Denial of service Excess Pods, API requests, CPU, memory or storage exhaust capacity Requests/limits, quotas, API flow control, rate limits and saturation alerts
Malicious execution Exploited application or poisoned image runs unwanted commands Patch/test code, verify artifacts, restrict runtime privilege and monitor execution
Network attack Interception, spoofed services or lateral movement to databases Verified TLS/mTLS, network segmentation, DNS protection and traffic evidence
Sensitive data access A token, mounted Secret, exposed etcd snapshot or log leaks data Least privilege, encryption, restricted mounts, redaction and access audits
Privilege escalation Broad RBAC, host mounts, privileged execution or kernel vulnerability Admission, scoped identities, patched nodes and reduced host access

Persistence is not persistent storage. It is an attacker's ability to retain or regain access. Deleting one malicious Pod may fail because a controller recreates it or stolen credentials still work. Investigate the authorized owner and configuration source; remove the persistence mechanism and revoke compromised access as part of recovery.

A container compromise is not automatically a host compromise, but shared kernels and dangerous settings can permit escalation. Similarly, a stolen service-account token is constrained by its permissions only if other paths, such as creating a Pod under a stronger identity, are also controlled. Think in chains rather than one isolated control.

STRIDE prompts six questions: spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege. MITRE ATT&CK for Containers catalogs observed adversary techniques and tactics. STRIDE helps ask what could go wrong; ATT&CK helps organize recognizable attacker behavior. Neither tool automatically measures or eliminates every risk.

During response, follow an agreed plan: validate the signal, preserve relevant evidence, contain exposure, remove persistence, rotate affected credentials, rebuild from trusted artifacts and verify recovery. Keep investigation evidence outside the compromised workload's control. Choose containment with awareness of availability and evidence loss; indiscriminate deletion can hide the original cause.

Choose under exam pressure

Requirement Choice and reason
A removed malicious Pod keeps returning Inspect its owner, controllers and declarative source; remove persistence and compromised credentials.
Rank a vulnerability for remediation Assess exposure and business impact as well as severity; record the decision.
Understand data leakage between services Trace identities, data flow and network/storage trust boundaries.
Classify unexpected cryptomining activity Consider malicious execution plus resource exhaustion; investigate the entry and persistence paths.

Traps

  • Network location does not prove workload identity.
  • An ephemeral container can still steal persistent credentials or create durable API objects.
  • Fixing one visible symptom does not remove every step in the attack chain.
  • Security response should preserve useful evidence before destructive recovery steps where feasible.

Active recall

1. A CronJob recreates an unauthorized Pod after deletion. Which threat goal is illustrated?

Persistence: the attacker retains a mechanism that reestablishes access or execution.

2. What distinguishes a vulnerability from risk?

A vulnerability is a weakness. Risk considers the likelihood and impact of its exploitation in the actual environment.

3. What does the R in STRIDE represent?

Repudiation: actions cannot be reliably attributed or proven. Protected audit evidence helps address it.

4. Can a read-only root filesystem stop all exfiltration?

No. A process may still read accessible data and send it over permitted network paths. Restrict data access and egress as well.

5. Why investigate ServiceAccount permissions after an application compromise?

The attacker may use the workload identity to read sensitive objects, create workloads or move to stronger privileges.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.