Linux Foundation CKS - Practice Exam (New)

所在平台: Udemy

课程主页: https://www.udemy.com/course/linux-foundation-cks-2022-practice-exam/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:Linux Foundation CKS - 模拟考试(新) 课程概述: 本课程提供了多个模拟考试,帮助考生准备认证的Kubernetes安全专家(CKS)考试。需要注意的是,本课程不提供任何实践实验,主要侧重于从理论角度准备考试。报名之前,考生需具备CKA的前置知识,并在参加CKS考试前掌握以下内容: 1. **集群设置(10%)** - 使用网络安全策略限制集群级别的访问 - 依据CIS基准审查Kubernetes组件(etcd、kubelet、kubedns、kubeapi)的安全配置 - 正确设置Ingress对象及其安全控制 - 保护节点元数据和端点 - 最小化对GUI元素的使用和访问 - 部署前验证平台二进制文件 2. **集群硬化(15%)** - 限制对Kubernetes API的访问 - 使用基于角色的访问控制(RBAC)减少暴露面 - 小心使用服务账户,例如禁用默认账户,最小化新创建账户的权限 - 经常更新Kubernetes - 最小化主机操作系统的占用(减少攻击面) - 最小化IAM角色 - 限制外部对网络的访问 - 适当使用内核硬化工具,如AppArmor和seccomp 3. **系统硬化(15%)** - 最小化主机操作系统的占用(减少攻击面) - 最小化IAM角色 - 限制外部对网络的访问 - 适当使用内核硬化工具,如AppArmor和seccomp 4. **最小化微服务漏洞(20%)** - 设置适当的操作系统级别安全域,如使用PSP、OPA、安全上下文 - 管理Kubernetes密钥 - 在多租户环境中使用容器运行时沙箱(如gvisor、kata容器) - 通过使用mTLS实现Pod到Pod的加密 5. **供应链安全(20%)** - 最小化基础镜像的占用 - 确保供应链安全:列出允许的镜像注册表,签名并验证镜像 - 对用户工作负载进行静态分析(如Kubernetes资源、Docker文件) - 扫描镜像以发现已知漏洞 6. **监控、日志记录和运行时安全(20%)** - 在主机和容器级别进行系统调用过程和文件活动的行为分析,以检测恶意活动 - 检测物理基础设施、应用程序、网络、数据、用户和工作负载中的威胁 - 检测所有攻击阶段,无论发生在何处及其传播方式 - 对环境中的坏演员进行深度分析和识别 - 确保容器在运行时的不可变性 - 使用审计日志监控访问 这套模拟考试的复杂度中到高,将帮助您掌握CKS考试所需的技能,并提供详细的题目解释以及官方文档的参考。

课程评论(0条)

课程详情

This course offers multiple mock exams to prepare for Certified Kubernetes Security Specialist (CKS) exam. Take into account that this course doesn't give access to any hands-on labs and is focused primarily on preparing for the exam from the theorical point of view.Note - 1: Prior knowledge of CKA is required before enrollment.You must cover below curriculum before attempting CKS Exam:10% - Cluster SetupUse Network security policies to restrict cluster level accessUse CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)Properly set up Ingress objects with security controlProtect node metadata and endpointsMinimize use of, and access to, GUI elementsVerify platform binaries before deploying15% - Cluster HardeningRestrict access to Kubernetes APIUse Role Based Access Controls to minimize exposurehandy site collects together articles, tools and the official documentation all in one placeExercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created onesUpdate Kubernetes frequentlyMinimize host OS footprint (reduce attack surface)Minimize IAM rolesMinimize external access to the networkAppropriately use kernel hardening tools such as AppArmor, seccomp15% System HardeningMinimize host OS footprint (reduce attack surface)Minimize IAM rolesMinimize external access to the networkAppropriately use kernel hardening tools such as AppArmor, seccomp!? where is selinux? assume exam systems are ubuntu20% - Minimize Microservice VulnerabilitiesSetup appropriate OS level security domains e.g. using PSP, OPA, security contextsManage kubernetes secretsUse container runtime sandboxes in multi-tenant environments (e.g. gvisor, kata containers)Implement pod to pod encryption by use of mTLS20% - Supply Chain SecurityMinimize base image footprintSecure your supply chain: whitelist allowed image registries, sign and validate imagesUse static analysis of user workloads (e.g. kubernetes resources, docker files)Scan images for known vulnerabilities20% - Monitoring, Logging and Runtime SecurityPerform behavioral analytics of syscall process and file activities at the host and container level to detect malicious activitiesDetect threats within physical infrastructure, apps, networks, data, users and workloadsDetect all phases of attack regardless where it occurs and how it spreadsPerform deep analytical investigation and identification of bad actors within environmentEnsure immutability of containers at runtimeUse Audit Logs to monitor accessThese mock exams are of intermediate to high complexity that will give you the required skills to master the CKS exam and include detailed explanations of the questions, as well as references to the official documentation.

课程标签

0人关注该课程

主题相关的课程