Your cluster is 92% conformant to its hardening benchmark — is the remaining 8% 8% of your risk?
answer
- a count of settings, equally weighted
- not a ranked control set
- non-linear in both directions
- name the load-bearing few instead
- the starting position picks the list
basics
~20 sNo. The percentage is an unweighted count of settings, not a ranked control set, so the same 92% is compatible with every load-bearing item failing and with every failing item being irrelevant. Defend the number by naming the handful of items that remove something your adversary depends on.
solid answer
~50 sThe number is a count: of the items the standard defines and that were checked, 92% were at the recommended value. Every item counts one, whether it removes an adversary's only path to a node or governs a file path on a control plane you do not operate. So the relationship between the remaining 8% and risk is not linear in either direction — the same score is compatible with all fifteen failures being naming conventions, and with the one item holding the roof up being among them. To defend 92% I would name the small set of items I treat as load-bearing for this estate and their state, and say why the other one hundred and eighty are hygiene here. And the load-bearing set depends on where the adversary starts: against a criminal who simply bought a valid workload credential from a broker, every item on the authentication path is green and worth nothing, because they authenticate legitimately.
go deeper
Remember that the percentage counts settings, each one worth the same, so it cannot be read as a share of risk. Being able to say that plainly is already the right answer at this level.
Explain why the arithmetic fails in both directions, and give one concrete failing item that would matter and one that would not for a Kubernetes estate.
Show the move an interviewer is waiting for: replace the percentage with a named load-bearing set, its condition, and the reasoning that picked it — including how the adversary's starting position changes which items count.
Be ready to say what you report upward and outward when the percentage is what leadership or a customer tracks, and how you keep the honest inner list from being quietly replaced by the flattering outer one.
## What the number is "92% conformant" asserts one thing: of the items in that standard which were evaluated against this cluster, 92% were found at the recommended value at the time they were looked at. It is a count with an equal weight per item. It is not a percentage of risk, not a percentage of attack paths, and not a percentage of anything an adversary experiences. The wrong answer this question exists to catch is fluent and comes from good engineers: "we're at 92%, so the remaining 8% is 8% of the risk." The correcting fact is short — a hardening benchmark is a broad-applicability settings list, not a ranked control set — and the consequence is that the relationship between item count and technique removal is not linear **in any direction**. ## Both failure directions are real - **The score is too flattering.** Fifteen failing items out of two hundred, and one of them is the node agent accepting unauthenticated callers. The other fourteen are file paths on a control plane you do not run. You are at 92% and an adversary who can route to a node port has command execution inside every container on it. - **The score is too harsh.** Fifteen failing items, all of them ownership and naming conventions on components you never installed, while every item that takes something from an adversary is green. You are at 92% and there is nothing here worth a sprint. Both are ordinary. Neither is visible in the number, and no amount of precision in the number fixes that, because the defect is in the weighting, not the measurement. ## How to defend the number in the room Do not defend the percentage. Replace it, in the same breath, with a short list: 1. **Name the load-bearing set for this estate** — typically a handful of items, not a hundred. For a Kubernetes estate: the node agent's authentication and authorization path; whether workload identities are granted anything beyond what they need; whether the credentials handed to workloads are short-lived and bound rather than long-lived; whether the admission path will accept a workload asking for the host filesystem or host namespaces. 2. **State each one's condition** — green or red, no percentage. 3. **Say why the rest is hygiene here** — usually a sentence about what you operate and what you do not. 4. **Say what would change the list.** A new component, a control plane you start operating yourself, a change in who can reach the node network. That answer survives a skeptical interviewer. "92%" does not, because the obvious next question — *which* 8% — has no good answer if you never sorted the list. ## The starting position decides the list The most useful correction to make out loud is that the load-bearing set is a function of where the adversary starts, not a property of the standard. Consider a criminal who never exploited anything. They bought a valid workload credential for your cluster from a broker who had it from somewhere else entirely. They now start *inside*, authenticating legitimately. Ask which items still bind them: - **Everything on the authentication path is irrelevant.** Anonymous access disabled, strong authentication on the API server, certificate hygiene — all green, all satisfied, all worth exactly nothing here, because the caller presents a credential the cluster is supposed to accept. - **What binds them is what that identity may do.** Whether the account is scoped to what its workload needs or carries broad verbs across namespaces. Whether the credential is a short-lived, audience-bound token that expires or a long-lived one that works for a year. Whether the admission path lets that identity schedule a workload that mounts the host filesystem, which is how a modest identity becomes a node. So two estates at the same 92% can be in completely different positions, and the difference is not in the score — it is in which of the four buckets the failures fall into and which adversary you actually have. ## What the number is still good for It is not useless. It is a drift signal on a list somebody sane wrote, it is comparable across organisations precisely because nobody tailored it, and a sudden fall is worth looking at. What it cannot do is stand in for the sort. Report it, and never let it be the only number in the conversation. ## The one-line answer No — the score is unweighted by technique removal, so 8% of the items is not 8% of anything an adversary cares about. Ask which items are failing, then ask which of them takes something away from an adversary who starts where yours starts.
- An intruder bought a valid workload credential rather than exploiting anything — which items still bind them?Only the ones that constrain a legitimate identity. What that account is allowed to do, whether its credential is short-lived and bound rather than long-lived, and whether the admission path would accept a workload from it that mounts the host filesystem or host namespaces. Every item on the authentication path is green and irrelevant, because the caller authenticates the way the cluster intends.
- Would raising the score from 92% to 100% be a good use of a quarter?Only if the failing items include load-bearing ones. If the failures are naming and path items for components you do not run, the quarter buys a rounder number and no change in exposure, while the load-bearing set stays wherever it already was. Sort the failures first, then decide; the sort is cheap and the quarter is not.
- Is the percentage worth reporting at all?Yes, as a drift signal on a list nobody in your organisation chose, and as something comparable with other organisations. It just must never be the only number. Report it alongside the state of the named load-bearing set, so a green outward figure cannot hide a red inner one.
- How do you answer 'which 8%?' if nobody has sorted the list?Honestly, and then do the sort — it is usually an hour's work for a couple of hundred items, because most sort themselves. Guessing which failures matter in front of a skeptic is worse than saying the sort has not been done and giving a date, since the follow-up question is always what the failing items let an adversary do.
It is like reporting that 92% of a building's fittings match the code. That figure is compatible with every window being compliant and the front door standing open, and with the only failures being the colour of the fire-door signage.
saying these in an interview costs you the question
- Treats the failing percentage as a share of risk
- Assumes failures are the least important items
- Says the score proves attack paths were closed
- Cannot name a single load-bearing item for the estate
- Ignores that the load-bearing set depends on the adversary's start