skip to content

Your cluster is 92% conformant to its hardening benchmark — is the remaining 8% 8% of your risk?

level: seniorimportance: must knowfreq 60%

answer

  1. a count of settings, equally weighted
  2. not a ranked control set
  3. non-linear in both directions
  4. name the load-bearing few instead
  5. the starting position picks the list

basics

~20 s

No. The percentage is an unweighted count of settings, not a ranked control set, so the same 92% is compatible with every load-bearing item failing and with every failing item being irrelevant. Defend the number by naming the handful of items that remove something your adversary depends on.

solid answer

~50 s

The number is a count: of the items the standard defines and that were checked, 92% were at the recommended value. Every item counts one, whether it removes an adversary's only path to a node or governs a file path on a control plane you do not operate. So the relationship between the remaining 8% and risk is not linear in either direction — the same score is compatible with all fifteen failures being naming conventions, and with the one item holding the roof up being among them. To defend 92% I would name the small set of items I treat as load-bearing for this estate and their state, and say why the other one hundred and eighty are hygiene here. And the load-bearing set depends on where the adversary starts: against a criminal who simply bought a valid workload credential from a broker, every item on the authentication path is green and worth nothing, because they authenticate legitimately.

go deeper

for a junior

Remember that the percentage counts settings, each one worth the same, so it cannot be read as a share of risk. Being able to say that plainly is already the right answer at this level.

for a middle

Explain why the arithmetic fails in both directions, and give one concrete failing item that would matter and one that would not for a Kubernetes estate.

for a senior

Show the move an interviewer is waiting for: replace the percentage with a named load-bearing set, its condition, and the reasoning that picked it — including how the adversary's starting position changes which items count.

for a principal

Be ready to say what you report upward and outward when the percentage is what leadership or a customer tracks, and how you keep the honest inner list from being quietly replaced by the flattering outer one.

## What the number is "92% conformant" asserts one thing: of the items in that standard which were evaluated against this cluster, 92% were found at the recommended value at the time they were looked at. It is a count with an equal weight per item. It is not a percentage of risk, not a percentage of attack paths, and not a percentage of anything an adversary experiences. The wrong answer this question exists to catch is fluent and comes from good engineers: "we're at 92%, so the remaining 8% is 8% of the risk." The correcting fact is short — a hardening benchmark is a broad-applicability settings list, not a ranked control set — and the consequence is that the relationship between item count and technique removal is not linear **in any direction**. ## Both failure directions are real - **The score is too flattering.** Fifteen failing items out of two hundred, and one of them is the node agent accepting unauthenticated callers. The other fourteen are file paths on a control plane you do not run. You are at 92% and an adversary who can route to a node port has command execution inside every container on it. - **The score is too harsh.** Fifteen failing items, all of them ownership and naming conventions on components you never installed, while every item that takes something from an adversary is green. You are at 92% and there is nothing here worth a sprint. Both are ordinary. Neither is visible in the number, and no amount of precision in the number fixes that, because the defect is in the weighting, not the measurement. ## How to defend the number in the room Do not defend the percentage. Replace it, in the same breath, with a short list: 1. **Name the load-bearing set for this estate** — typically a handful of items, not a hundred. For a Kubernetes estate: the node agent's authentication and authorization path; whether workload identities are granted anything beyond what they need; whether the credentials handed to workloads are short-lived and bound rather than long-lived; whether the admission path will accept a workload asking for the host filesystem or host namespaces. 2. **State each one's condition** — green or red, no percentage. 3. **Say why the rest is hygiene here** — usually a sentence about what you operate and what you do not. 4. **Say what would change the list.** A new component, a control plane you start operating yourself, a change in who can reach the node network. That answer survives a skeptical interviewer. "92%" does not, because the obvious next question — *which* 8% — has no good answer if you never sorted the list. ## The starting position decides the list The most useful correction to make out loud is that the load-bearing set is a function of where the adversary starts, not a property of the standard. Consider a criminal who never exploited anything. They bought a valid workload credential for your cluster from a broker who had it from somewhere else entirely. They now start *inside*, authenticating legitimately. Ask which items still bind them: - **Everything on the authentication path is irrelevant.** Anonymous access disabled, strong authentication on the API server, certificate hygiene — all green, all satisfied, all worth exactly nothing here, because the caller presents a credential the cluster is supposed to accept. - **What binds them is what that identity may do.** Whether the account is scoped to what its workload needs or carries broad verbs across namespaces. Whether the credential is a short-lived, audience-bound token that expires or a long-lived one that works for a year. Whether the admission path lets that identity schedule a workload that mounts the host filesystem, which is how a modest identity becomes a node. So two estates at the same 92% can be in completely different positions, and the difference is not in the score — it is in which of the four buckets the failures fall into and which adversary you actually have. ## What the number is still good for It is not useless. It is a drift signal on a list somebody sane wrote, it is comparable across organisations precisely because nobody tailored it, and a sudden fall is worth looking at. What it cannot do is stand in for the sort. Report it, and never let it be the only number in the conversation. ## The one-line answer No — the score is unweighted by technique removal, so 8% of the items is not 8% of anything an adversary cares about. Ask which items are failing, then ask which of them takes something away from an adversary who starts where yours starts.

  • An intruder bought a valid workload credential rather than exploiting anything — which items still bind them?
    Only the ones that constrain a legitimate identity. What that account is allowed to do, whether its credential is short-lived and bound rather than long-lived, and whether the admission path would accept a workload from it that mounts the host filesystem or host namespaces. Every item on the authentication path is green and irrelevant, because the caller authenticates the way the cluster intends.
  • Would raising the score from 92% to 100% be a good use of a quarter?
    Only if the failing items include load-bearing ones. If the failures are naming and path items for components you do not run, the quarter buys a rounder number and no change in exposure, while the load-bearing set stays wherever it already was. Sort the failures first, then decide; the sort is cheap and the quarter is not.
  • Is the percentage worth reporting at all?
    Yes, as a drift signal on a list nobody in your organisation chose, and as something comparable with other organisations. It just must never be the only number. Report it alongside the state of the named load-bearing set, so a green outward figure cannot hide a red inner one.
  • How do you answer 'which 8%?' if nobody has sorted the list?
    Honestly, and then do the sort — it is usually an hour's work for a couple of hundred items, because most sort themselves. Guessing which failures matter in front of a skeptic is worse than saying the sort has not been done and giving a date, since the follow-up question is always what the failing items let an adversary do.

It is like reporting that 92% of a building's fittings match the code. That figure is compatible with every window being compliant and the front door standing open, and with the only failures being the colour of the fire-door signage.

saying these in an interview costs you the question

  • Treats the failing percentage as a share of risk
  • Assumes failures are the least important items
  • Says the score proves attack paths were closed
  • Cannot name a single load-bearing item for the estate
  • Ignores that the load-bearing set depends on the adversary's start

context