CKS exam preparation cheat sheets
Preparation for CKS exam (Certified Kubernetes Security Specialist)
Topics:
- CKS exam introduction
- Custer Setup and Hardering
- System Hardering
- Minimize microservice Vulnerabilities
- Supply chain security
- Monitoring, Logging and Runtime security
- Exam tips
CKS exam introduction
Custer Setup and Hardering
- CIS benchmark and kube-bench
- Service Accounts
- TLS in Kubernetes
- API groups
- Authorization
- RBAC
- Cluster upgrade process
- Kubelet
- Network policies
- Ingress
- Docker service security
- Kubectl Proxy & Port Forward
- Auditing
System Hardering
- Minimize host OS footprint
- Apparmor
- Seccomp
- Limit node access
- SSH hardering
- Minimize external access to network
- Restrict Kernel modules
- Linux privilege escalation
Minimize microservice Vulnerabilities
- Security Contexts
- Adminssions Controllers
- Pod security policies
- Open Policy Agent OPA
- gVisor
- kata Containers
- Control Plane isolation
- Data plane Isolation
- Pod-to-pod encryption
- Cilium
- QoS
Supply chain security
Monitoring, Logging and Runtime security
Exam tips
Official Documentation
- Kubernetes Official Documentation
- Kubernetes Security Documentation
- Kubernetes Security Best Practices
- Kubernetes Security Checklist