Certified Kubernetes Security Specialist (CKS) Cert Prep

Certified Kubernetes Security Specialist (CKS) Cert Prep

19h 40mIntermediate2025-04-03

Authors

Pearson

Pearson

Chris Jackson

Chris Jackson

Course details

The Certified Kubernetes Security Specialist (CKS) certification was created by the Linux Foundation and the Cloud Native Computing Foundation (CNCF) as part of an ongoing effort to help develop the Kubernetes ecosystem. In this course, instructor Chris Jackson covers the core concepts and technical skills you need to tackle the official exam. Explore the six domains of the CKS exam, including cluster setup, cluster hardening, system hardening, minimizing microservice vulnerabilities, supply chain security, and monitoring, logging, and runtime security. Along the way, be sure to test your new skills in the practice exam scenarios at the end of the course.

Skills covered

KubernetesDevOps ToolsIncident ResponseDevOpsCert PrepCybersecurityOpen Source

Concepts

Introduction

  • Certified Kubernetes Security Specialist (CKS) - Introduction

Getting CKS Certified

  • Module 1 - Preparing for the CKS exam introduction
  • Learning objectives
  • CKS certification requirements
  • Resources and study tools
  • Practice strategy
  • Creating a study timeline and expectations

Building Your K8s Home Lab

  • Learning objectives
  • Lab environment and architecture
  • Local installation
  • Cloud installation
  • Your cluster up and running

Kubernetes Security Foundation

  • Learning objectives
  • Cloud native security
  • Kubernetes architecture
  • Kubernetes PKI architecture
  • Threat modeling K8s
  • Real world K8s hacks
  • OWASP kubernetes top 10

Network Security Policies

  • Module 2 - Kubernetes cluster setup introduction
  • Learning objectives
  • Network security overview
  • Pod communication policies
  • Segmentation

CIS Benchmark Review of Kubernetes Components

  • Learning objectives
  • CIS benchmarks for Kubernetes
  • Install kube-bench
  • Checking compliance with kube-bench

Properly Set Up Ingress with TLS

  • Learning objectives
  • Understanding ingress
  • Creating ingress objects
  • Ingress security options
  • Testing ingress access

Protect Node Metadata and Endpoints

  • Learning objectives
  • Understanding kubelet
  • Network policies
  • Node metadata protection
  • Implement kubelet authentication
  • Test kubelet and node metadata security

Kubernetes Dashboard Security

  • Learning objectives
  • K8s dashboard architecture
  • Dashboard installation
  • Role-based access control (RBAC)

Verify Platform Binaries Before Deploying

  • Learning objectives
  • Understanding platform binary integrity
  • Download the latest Kubernetes release
  • Verify binary checksum

Restrict Access to Kubernetes API

  • Module 3 - Cluster hardening introduction
  • Learning objectives
  • Kubernetes API fundamentals
  • Kubernetes access control
  • API server configuration
  • API server hardening
  • Verify access control policies

Role Based Access Control (RBAC)

  • Learning objectives
  • Understanding Kubernetes RBAC
  • Creating a user account
  • Applying roles to a user
  • Configuring and binding cluster roles
  • Verifying role rules

Protecting Service Accounts

  • Learning objectives
  • Understanding service accounts
  • Creating a service account
  • Disable default settings
  • Verify service account permissions

Upgrade Kubernetes to Avoid Vulnerabilities

  • Learning objectives
  • Kubernetes update process
  • Plan upgrade process
  • Upgrade components and test

Minimize Host OS Footprint

  • Module 4 - System hardening introduction
  • Learning objectives
  • Host hardening
  • Remove unneeded services
  • Log system activities
  • Limit access

Minimize External Access to the Network

  • Learning objectives
  • Understanding external access to Kubernetes
  • Finding open ports
  • Host firewall configuration
  • Test host firewall

Kernel Hardening

  • Learning objectives
  • Understanding kernel threats
  • Using seccomp
  • Using AppArmor
  • Testing kernel security

Use Least Privilege IAM

  • Learning objectives
  • Principle of least privilege
  • Host-based IAM
  • Restricting user privileges
  • Controlling file access and user logging
  • Understanding cloud RBAC

Use Appropriate Pod Security Standards

  • Module 5 - Minimize microservice vulnerabilities introduction
  • Learning objectives
  • Understanding pod security
  • Configure security contexts
  • Pod security admission
  • OPA gatekeeper

Managing Kubernetes Secrets

  • Learning objectives
  • Understanding Kubernetes secrets
  • Creating and using a secret
  • Using secrets in pods
  • Encrypting secrets at rest

Implement Container Isolation Techniques

  • Learning objectives
  • Containing containers
  • Sandboxed pods
  • Using qVisor
  • Using Kata containers

Implement Pod-to-Pod Encryption with Cilium

  • Learning objectives
  • Introduction to Cilium and mTLS
  • Using Cilium for pod-to-pod encryption
  • Deploying and verifying mTLS with Cilium

Secure Your Software Supply Chain

  • Module 6 - Software supply chain security introduction
  • Learning objectives
  • Software supply chain risks
  • Protect image registry access
  • Require signed images
  • Policy enforcement - Image policy webhook
  • Policy enforcement - Validating admission policy

Static Analysis of Workloads and Containers

  • Learning objectives
  • Static analysis fundamentals
  • Scan manifests for vulnerabilities with kube-linter
  • Scanning for cluster vulnerabilities

Minimize Base Image Footprint

  • Learning objectives
  • Understanding container images
  • Use image creation good practices
  • Reduce image attack surface

Scan Images for Known Vulnerabilities

  • Learning objectives
  • Scanning for vulnerable images
  • Using Trivy to identify vulnerable containers
  • Using the Trivy operator
  • Using Trivy and Kyverno for SBOM attestation

Ensure Immutability of Containers at Runtime

  • Module 7 - Monitoring, logging, and runtime security introduction
  • Learning objectives
  • Understanding immutability
  • Read only filesystem
  • Policy enforcement with VAP

Use Kubernetes Audit Logs to Monitor Access

  • Learning objectives
  • Auditing in Kubernetes
  • Define an audit policy
  • Event batching and tuning
  • Configure backend log storage

Detect Malicious Activity, Threats, and Attacks

  • Learning objectives
  • Understanding syscall behavioral analysis
  • Using Falco for threat detection
  • Falco host installation
  • Falco Kubernetes installation
  • Falco configuration and rules
  • Falco custom rules in action

Investigate and Identify Signs of Compromise

  • Learning objectives
  • MITRE ATT&CK framework
  • Security event log review
  • Gathering evidence of compromise
  • Practicing Kubernetes security

CKS Practice Exam 1

  • Module 8 - Exam practice scenarios introduction
  • Learning objectives
  • Securing Kubernetes API access
  • Implementing pod security standards (PSS)
  • Enforcing network policies for pod communication
  • Restricting image registries
  • Configuring secret encryption

CKS Practice Exam 2

  • Learning objectives
  • Container runtime security
  • Detecting malicious behavior using Falco
  • Enforcing network encryption
  • Secure ingress via TLS
  • Detecting and mitigating security vulnerabilities

Summary

  • Certified Kubernetes Security Specialist (CKS) - Summary
250,000 Toman