APURV
  • Home
  • Journey
  • Projects
  • Blogs
  • Interview
  • Exams
Resume
APURV

Building scalable, secure, and production-ready cloud infrastructure. Automation first.

NAVIGATION

HomeExperienceProjectsCertificationsSkills

TECH STACK

AWSGCPK8sCI/CDLinuxDocker

CONNECT

LinkedInGitHubEmailResume

© 2026 Apurv Gujjar. All rights reserved.
Apurv Gujjar
Apurv GujjarDevOps & Cloud Engineer
|Interview Documentation
Portfolio
Handbooks
🎯Linux🐙Git & GitHub🤖GitHub Actions🌐Networking☁AWS🛠Terraform🐳Docker☸Kubernetes📊Monitoring🛡DevSecOps💰Cost Optimization🚨Incident Scenarios👤HR & Behavioral☁GCP🐍Python
Interview DocumentationDockerHow do Linux capabilities, seccomp profiles, AppArmor/SELinux, and Trivy fit into securing containers in production?
Back to all Docker questions
Q1

How do Linux capabilities, seccomp profiles, AppArmor/SELinux, and Trivy fit into securing containers in production?

💬Answer
  • Linux Capabilities: Linux splits root permissions into smaller, distinct capabilities (e.g., CAP_NET_ADMIN, CAP_SYS_ADMIN). Docker strips all non-essential capabilities from container roots by default. You can drop all capabilities and add only what is needed: --cap-drop=ALL --cap-add=NET_BIND_SERVICE.
  • seccomp (Secure Computing Mode): Filters system calls (syscalls) made by container processes. Docker applies a default seccomp profile that blocks dangerous syscalls (like reboot or ptrace).
  • AppArmor / SELinux: Linux Security Modules that enforce mandatory access controls (MAC) on containers, restricting which files, directories, and ports a container can access on the host.
  • Trivy: A simple, comprehensive vulnerability scanner for container images. Run Trivy in your CI/CD pipelines (trivy image <image-name>) to detect OS package and dependency vulnerabilities (CVEs) before pushing to production registries.

Related Docker Questions

View All DockerQuestions →
Q1

How would you explain the difference between a container and a virtual machine to someone new to DevOps?

Q2

What is Docker, and what specific advantages does it bring to the software development lifecycle?

Q3

Can you walk me through the low-level container runtime stack (runc, containerd, CRI-O)? What actually happens under the hood when 'docker run' executes?

Q4

# Execution flow of `docker run`:

Apurv Gujjar - DevOps & Cloud Engineer
Created by

Apurv Gujjar

DevOps & Cloud Engineer

Specialized in:DevOpsAWSGCPKubernetesTerraformDocker
View Portfolio