Certified Kubernetes Security Specialist (CKS) Cert Prep
19h 40mIntermediate2025-04-03
Authors

Pearson

Chris Jackson
Course details
The Certified Kubernetes Security Specialist (CKS) certification was created by the Linux Foundation and the Cloud Native Computing Foundation (CNCF) as part of an ongoing effort to help develop the Kubernetes ecosystem. In this course, instructor Chris Jackson covers the core concepts and technical skills you need to tackle the official exam. Explore the six domains of the CKS exam, including cluster setup, cluster hardening, system hardening, minimizing microservice vulnerabilities, supply chain security, and monitoring, logging, and runtime security. Along the way, be sure to test your new skills in the practice exam scenarios at the end of the course.
Skills covered
KubernetesDevOps ToolsIncident ResponseDevOpsCybersecurityCert PrepOpen Source
Concepts
0. Introduction
- 01 - Certified Kubernetes Security Specialist (CKS) - Introduction
1. Getting CKS Certified
- 02 - Module 1 - Preparing for the CKS exam introduction
- 03 - Learning objectives
- 04 - CKS certification requirements
- 05 - Resources and study tools
- 06 - Practice strategy
- 07 - Creating a study timeline and expectations
2. Building Your K8s Home Lab
- 08 - Learning objectives
- 09 - Lab environment and architecture
- 10 - Local installation
- 11 - Cloud installation
- 12 - Your cluster up and running
3. Kubernetes Security Foundation
- 13 - Learning objectives
- 14 - Cloud native security
- 15 - Kubernetes architecture
- 16 - Kubernetes PKI architecture
- 17 - Threat modeling K8s
- 18 - Real world K8s hacks
- 19 - OWASP kubernetes top 10
4. Network Security Policies
- 20 - Module 2 - Kubernetes cluster setup introduction
- 21 - Learning objectives
- 22 - Network security overview
- 23 - Pod communication policies
- 24 - Segmentation
5. CIS Benchmark Review of Kubernetes Components
- 25 - Learning objectives
- 26 - CIS benchmarks for Kubernetes
- 27 - Install kube-bench
- 28 - Checking compliance with kube-bench
6. Properly Set Up Ingress with TLS
- 29 - Learning objectives
- 30 - Understanding ingress
- 31 - Creating ingress objects
- 32 - Ingress security options
- 33 - Testing ingress access
7. Protect Node Metadata and Endpoints
- 34 - Learning objectives
- 35 - Understanding kubelet
- 36 - Network policies
- 37 - Node metadata protection
- 38 - Implement kubelet authentication
- 39 - Test kubelet and node metadata security
8. Kubernetes Dashboard Security
- 40 - Learning objectives
- 41 - K8s dashboard architecture
- 42 - Dashboard installation
- 43 - Role-based access control (RBAC)
9. Verify Platform Binaries Before Deploying
- 44 - Learning objectives
- 45 - Understanding platform binary integrity
- 46 - Download the latest Kubernetes release
- 47 - Verify binary checksum
10. Restrict Access to Kubernetes API
- 48 - Module 3 - Cluster hardening introduction
- 49 - Learning objectives
- 50 - Kubernetes API fundamentals
- 51 - Kubernetes access control
- 52 - API server configuration
- 53 - API server hardening
- 54 - Verify access control policies
11. Role Based Access Control (RBAC)
- 55 - Learning objectives
- 56 - Understanding Kubernetes RBAC
- 57 - Creating a user account
- 58 - Applying roles to a user
- 59 - Configuring and binding cluster roles
- 60 - Verifying role rules
12. Protecting Service Accounts
- 61 - Learning objectives
- 62 - Understanding service accounts
- 63 - Creating a service account
- 64 - Disable default settings
- 65 - Verify service account permissions
13. Upgrade Kubernetes to Avoid Vulnerabilities
- 66 - Learning objectives
- 67 - Kubernetes update process
- 68 - Plan upgrade process
- 69 - Upgrade components and test
14. Minimize Host OS Footprint
- 70 - Module 4 - System hardening introduction
- 71 - Learning objectives
- 72 - Host hardening
- 73 - Remove unneeded services
- 74 - Log system activities
- 75 - Limit access
15. Minimize External Access to the Network
- 76 - Learning objectives
- 77 - Understanding external access to Kubernetes
- 78 - Finding open ports
- 79 - Host firewall configuration
- 80 - Test host firewall
16. Kernel Hardening
- 81 - Learning objectives
- 82 - Understanding kernel threats
- 83 - Using seccomp
- 84 - Using AppArmor
- 85 - Testing kernel security
17. Use Least Privilege IAM
- 86 - Learning objectives
- 87 - Principle of least privilege
- 88 - Host-based IAM
- 89 - Restricting user privileges
- 90 - Controlling file access and user logging
- 91 - Understanding cloud RBAC
18. Use Appropriate Pod Security Standards
- 92 - Module 5 - Minimize microservice vulnerabilities introduction
- 93 - Learning objectives
- 94 - Understanding pod security
- 95 - Configure security contexts
- 96 - Pod security admission
- 97 - OPA gatekeeper
19. Managing Kubernetes Secrets
- 98 - Learning objectives
- 99 - Understanding Kubernetes secrets
- 100 - Creating and using a secret
- 101 - Using secrets in pods
- 102 - Encrypting secrets at rest
20. Implement Container Isolation Techniques
- 103 - Learning objectives
- 104 - Containing containers
- 105 - Sandboxed pods
- 106 - Using qVisor
- 107 - Using Kata containers
21. Implement Pod-to-Pod Encryption with Cilium
- 108 - Learning objectives
- 109 - Introduction to Cilium and mTLS
- 110 - Using Cilium for pod-to-pod encryption
- 111 - Deploying and verifying mTLS with Cilium
22. Secure Your Software Supply Chain
- 112 - Module 6 - Software supply chain security introduction
- 113 - Learning objectives
- 114 - Software supply chain risks
- 115 - Protect image registry access
- 116 - Require signed images
- 117 - Policy enforcement - Image policy webhook
- 118 - Policy enforcement - Validating admission policy
23. Static Analysis of Workloads and Containers
- 119 - Learning objectives
- 120 - Static analysis fundamentals
- 121 - Scan manifests for vulnerabilities with kube-linter
- 122 - Scanning for cluster vulnerabilities
24. Minimize Base Image Footprint
- 123 - Learning objectives
- 124 - Understanding container images
- 125 - Use image creation good practices
- 126 - Reduce image attack surface
25. Scan Images for Known Vulnerabilities
- 127 - Learning objectives
- 128 - Scanning for vulnerable images
- 129 - Using Trivy to identify vulnerable containers
- 130 - Using the Trivy operator
- 131 - Using Trivy and Kyverno for SBOM attestation
26. Ensure Immutability of Containers at Runtime
- 132 - Module 7 - Monitoring, logging, and runtime security introduction
- 133 - Learning objectives
- 134 - Understanding immutability
- 135 - Read only filesystem
- 136 - Policy enforcement with VAP
27. Use Kubernetes Audit Logs to Monitor Access
- 137 - Learning objectives
- 138 - Auditing in Kubernetes
- 139 - Define an audit policy
- 140 - Event batching and tuning
- 141 - Configure backend log storage
28. Detect Malicious Activity, Threats, and Attacks
- 142 - Learning objectives
- 143 - Understanding syscall behavioral analysis
- 144 - Using Falco for threat detection
- 145 - Falco host installation
- 146 - Falco Kubernetes installation
- 147 - Falco configuration and rules
- 148 - Falco custom rules in action
29. Investigate and Identify Signs of Compromise
- 149 - Learning objectives
- 150 - MITRE ATT&CK framework
- 151 - Security event log review
- 152 - Gathering evidence of compromise
- 153 - Practicing Kubernetes security
30. CKS Practice Exam 1
- 154 - Module 8 - Exam practice scenarios introduction
- 155 - Learning objectives
- 156 - Securing Kubernetes API access
- 157 - Implementing pod security standards (PSS)
- 158 - Enforcing network policies for pod communication
- 159 - Restricting image registries
- 160 - Configuring secret encryption
31. CKS Practice Exam 2
- 161 - Learning objectives
- 162 - Container runtime security
- 163 - Detecting malicious behavior using Falco
- 164 - Enforcing network encryption
- 165 - Secure ingress via TLS
- 166 - Detecting and mitigating security vulnerabilities
Summary
- 167 - Certified Kubernetes Security Specialist (CKS) - Summary