Book description
Exclusively on O'Reilly: Get more hands-on training and test your CKS exam readiness by working through the Certified Kubernetes Security Specialist (CKS) Exam Prep Labs playlist. This collection of interactive labs provides hands-on training that enhances the exam prep provided by this study guide.
Vulnerabilities in software and IT infrastructure pose a major threat to organizations. In response, the Cloud Native Computing Foundation (CNCF) developed the Certified Kubernetes Security Specialist (CKS) certification to verify an administrator's proficiency to protect Kubernetes clusters and the cloud native software they contain. This practical book helps you fully prepare for the certification exam by walking you through all of the topics covered.
Different from typical multiple-choice formats used by other certifications, this performance-based exam requires deep knowledge of the tasks it covers under intense time pressure. If you want to pass the CKS exam on the first go, author Benjamin Muschko shares his personal experience to help you learn the objectives, abilities, and tips and tricks you need to pass on the first attempt.
- Identify, mitigate, and/or minimize threats to cloud native applications and Kubernetes clusters
- Learn the ins and outs of Kubernetes's security features, and external tools for security detection and mitigation purposes
- Demonstrate competency to perform the responsibilities of a Kubernetes administrator or application developer with a security viewpoint
- Solve real-world Kubernetes problems in a hands-on, command-line environment
- Effectively navigate and solve questions during the CKS exam
Publisher resources
Table of contents
- Preface
- 1. Exam Details and Resources
- 2. Cluster Setup
- 3. Cluster Hardening
- 4. System Hardening
-
5. Minimizing Microservice Vulnerabilities
-
Setting Appropriate OS-Level Security Domains
- Scenario: An Attacker Misuses root User Container Access
- Understanding Security Contexts
- Enforcing the Usage of a Non-Root User
- Setting a Specific User and Group ID
- Avoiding Privileged Containers
- Scenario: A Developer Doesn’t Follow Pod Security Best Practices
- Understanding Pod Security Admission (PSA)
- Enforcing Pod Security Standards for a Namespace
- Understanding Open Policy Agent (OPA) and Gatekeeper
- Installing Gatekeeper
- Implementing an OPA Policy
- Managing Secrets
- Understanding Container Runtime Sandboxes
- Understanding Pod-to-Pod Encryption with mTLS
- Summary
- Exam Essentials
- Sample Exercises
-
Setting Appropriate OS-Level Security Domains
-
6. Supply Chain Security
- Minimizing the Base Image Footprint
-
Securing the Supply Chain
- Signing Container Images
- Scenario: An Attacker Injects Malicious Code into a Container Image
- Validating Container Images
- Using Public Image Registries
- Scenario: An Attacker Uploads a Malicious Container Image
- Whitelisting Allowed Image Registries with OPA GateKeeper
- Whitelisting Allowed Image Registries with the ImagePolicyWebhook Admission Controller Plugin
- Implementing the Backend Application
- Configuring the ImagePolicyWebhook Admission Controller Plugin
- Static Analysis of Workload
- Scanning Images for Known Vulnerabilities
- Summary
- Exam Essentials
- Sample Exercises
- 7. Monitoring, Logging, and Runtime Security
- Appendix. Answers to Review Questions
- Index
- About the Author
Product information
- Title: Certified Kubernetes Security Specialist (CKS) Study Guide
- Author(s):
- Release date: June 2023
- Publisher(s): O'Reilly Media, Inc.
- ISBN: 9781098132972
You might also like
book
Certified Kubernetes Administrator (CKA) Study Guide
Exclusively on O'Reilly: Get more hands-on training and test your CKA exam readiness by working through …
book
Certified Kubernetes Administrator (CKA) Exam Guide
Develop a deep understanding of Kubernetes and the cloud native ecosystem, and pass the CKA exam …
video
Certified Kubernetes Security Specialist (CKS) Course
This Kubernetes Security Specialist course provides foundational knowledge using concepts and hands-on demonstrations of the Kubernetes …
video
Certified Kubernetes Administrator (CKA), 2nd Ed
11 Hours of Video Instruction An updated edition of this video title is available. Please go …