The Linux Foundation
The Linux Foundation Logo

Certified Kubernetes Security Specialist (CKS) 

  • Offered byThe Linux Foundation

Certified Kubernetes Security Specialist (CKS)
 at 
The Linux Foundation 
Overview

Demonstrate the abilities to secure container-based applications and Kubernetes platforms during build, deployment and runtime, and is qualified to perform these tasks in a professional setting

Duration

2 hours

Total fee

33,166

Mode of learning

Online

Official Website

Go to Website External Link Icon

Credential

Certificate

Certified Kubernetes Security Specialist (CKS)
 at 
The Linux Foundation 
Highlights

  • Earn a certificate from LinuxFoundationX
Details Icon

Certified Kubernetes Security Specialist (CKS)
 at 
The Linux Foundation 
Course details

What are the course deliverables?
  • Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
  • Properly set up Ingress objects with security control
  • Protect node metadata and endpoints
  • Minimize use of, and access to, GUI elements
  • Verify platform binaries before deploying
More about this course
  • CKS is a performance-based certification exam that tests candidates' knowledge of Kubernetes and cloud security in a simulated, real world environment
  • Candidates must have taken and passed the Certified Kubernetes Administrator (CKA) exam prior to attempting the CKS exam
  • CKS may be purchased but not scheduled until CKA certification has been achieved
  • A Certified Kubernetes Security Specialist (CKS) is an accomplished Kubernetes practitioner (must be CKA certified) who has demonstrated competence on a broad range of best practices for securing container-based applications and Kubernetes platforms during build, deployment and runtime

Certified Kubernetes Security Specialist (CKS)
 at 
The Linux Foundation 
Curriculum

Cluster Setup

Use Network security policies to restrict cluster level access

Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)

Properly set up Ingress objects with security control

Protect node metadata and endpoints

Minimize use of, and access to, GUI elements

Verify platform binaries before deploying

Cluster Hardening

Restrict access to Kubernetes API

Use Role Based Access Controls to minimize exposure

Exercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created ones

Update Kubernetes frequently

System Hardening

Minimize host OS footprint (reduce attack surface)

Minimize IAM roles

Minimize external access to the network

Appropriately use kernel hardening tools such as AppArmor, seccomp

Minimize Microservice Vulnerabilities

Setup appropriate OS level security domains e.g. using PSP, OPA, security contexts

Manage Kubernetes secrets

Use container runtime sandboxes in multi-tenant environments (e.g. gvisor, kata containers)

Implement pod to pod encryption by use of mTLS

Supply Chain Security

Minimize base image footprint

Secure your supply chain: whitelist allowed registries, sign and validate images

Use static analysis of user workloads (e.g.Kubernetes resources, Docker files)

Scan images for known vulnerabilities

Monitoring, Logging and Runtime Security

Perform behavioral analytics of syscall process and file activities at the host and container level to detect malicious activities

Detect threats within physical infrastructure, apps, networks, data, users and workloads

Detect all phases of attack regardless where it occurs and how it spreads

Perform deep analytical investigation and identification of bad actors within environment

Ensure immutability of containers at runtime

Use Audit Logs to monitor access

Certified Kubernetes Security Specialist (CKS)
 at 
The Linux Foundation 
Entry Requirements

Eligibility criteriaUp Arrow Icon
Conditional OfferUp Arrow Icon
  • Not mentioned

Other courses offered by The Linux Foundation

– / –
2 hours
Beginner
– / –
16 hours
Intermediate
– / –
60 hours
– / –
Free
1 hours
Beginner
View Other 4 CoursesRight Arrow Icon

Certified Kubernetes Security Specialist (CKS)
 at 
The Linux Foundation 
Students Ratings & Reviews

5/5
Verified Icon25 Ratings
P
Prasad Gummadavelli
Certified Kubernetes Security Specialist (CKS)
Offered by The Linux Foundation
5
Faculty: Fantastic Nice
Course Support: Ok
Reviewed on 12 Feb 2023Read More
Thumbs Up IconThumbs Down Icon
G
Guru Dayal Bhatt
Certified Kubernetes Security Specialist (CKS)
Offered by The Linux Foundation
5
Learning Experience: course content from kodecloud is excellent, impacted my career in terms of enhancing skill. Challenges is with psi application which linux foundation introduced.
Faculty: quality of lectures are good and it is having lab environment as well kodecloud, its updated on 1.25 version. Material is good and lab as well
Reviewed on 21 Jan 2023Read More
Thumbs Up IconThumbs Down Icon
A
amit kumar pandey
Certified Kubernetes Security Specialist (CKS)
Offered by The Linux Foundation
5
Learning Experience: It was excellent learning as lab was also included
Faculty: Excellent and experience holder they know which topic most of the students confused 100%
Course Support: Most of the companies are working on kubernetes now soit was the minimal requirement that candidate should have working knowledge of it
Reviewed on 15 Jan 2023Read More
Thumbs Up IconThumbs Down Icon
D
Debojit Debnath
Certified Kubernetes Security Specialist (CKS)
Offered by The Linux Foundation
5
Learning Experience: It was good i have learnt about Kubernetes fundamentals , i have learned it and got interest and currently pursuing for CKAD
Faculty: The session was very clear and very well explained and i highly enjoyed the content of the course and the way instructor handled the course. the course is very well structured and i have learned the basics very well and i highly recommend this course .
Reviewed on 23 Dec 2022Read More
Thumbs Up IconThumbs Down Icon
H
HEMANTH BITRA
Certified Kubernetes Security Specialist (CKS)
Offered by The Linux Foundation
5
Learning Experience: This course about how to adminstrate the kubernetes, how to take backup, keys skill how to deploy a container as a microservice and hand different scenario of handling kubernetes
Faculty: Faculty provided lab session with kodekloud and explains are very simple and easy to understand Kubernetes are upto date and fixing major vulnerability and this course is good for Devops and container technology knowledge
Reviewed on 3 Nov 2022Read More
Thumbs Up IconThumbs Down Icon
View All 12 ReviewsRight Arrow Icon
qna

Certified Kubernetes Security Specialist (CKS)
 at 
The Linux Foundation 

Student Forum

chatAnything you would want to ask experts?
Write here...