Practice Test -Certified Kubernetes Security Specialist(CKS)

所在平台: Udemy

课程主页: https://www.udemy.com/course/practice-test-certified-kubernetes-security-specialistcks/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:实践测试 - 认证Kubernetes安全专家(CKS) 概述:该课程为准备2025年认证Kubernetes安全专家(CKS)考试的学习者提供了必要的信息和实践测试。CKS考试的关键细节如下: - 题目数量:15个基于性能的任务 - 考试时长:2小时 - 通过分数:67% - 格式:在模拟环境中进行的动手操作、命令行考试 - 前提条件:考生必须持有有效的认证Kubernetes管理员(CKA)证书才能参加CKS考试。 考试内容侧重于实际的Kubernetes安全场景,涵盖如下领域: 1. 集群设置(15%) - 使用网络安全策略限制访问 - 将CIS基准应用于Kubernetes组件(如etcd、kubelet) - 使用TLS保护Ingress - 保护节点元数据和端点 - 在部署前验证平台二进制文件 2. 集群强化(15%) - 实施基于角色的访问控制(RBAC) - 安全管理服务账户 - 限制Kubernetes API访问 - 保持Kubernetes版本更新 3. 系统强化(10%) - 最小化主机操作系统占用 - 应用最小权限访问原则 - 限制外部网络访问 - 使用内核强化工具(如AppArmor、seccomp) 4. 最小化微服务漏洞(20%) - 应用Pod安全标准 - 安全管理Kubernetes秘密 - 使用隔离技术(如沙箱容器) - 实施Pod到Pod加密(如Cilium、Istio) 5. 供应链安全(20%) - 减少基础镜像大小 - 了解并保护软件供应链(如SBOM、CI/CD) - 使用受信任的注册处并验证工件 - 执行静态分析(如Kubesec、KubeLinter) 6. 监控、日志记录和运行时安全(20%) - 使用分析检测恶意行为 - 监控基础设施、应用和工作负载 - 调查攻击阶段和攻击者 - 确保容器在运行时不可变 - 有效使用Kubernetes审计日志 本课程旨在帮助学习者全面了解Kubernetes安全的重要性与实践,为CKS考试做好充分准备。

课程评论(0条)

课程详情

Here are the key details for the Certified Kubernetes Security Specialist (CKS) exam as of 2025:Number of Questions: 15 performance-based tasksExam Duration: 2 hoursPassing Score: 67%Format: Hands-on, command-line based exam in a simulated environmentPrerequisite: You must have a valid Certified Kubernetes Administrator (CKA) certification before taking the CKS.The exam focuses on real-world Kubernetes security scenarios, covering domains such as:Cluster HardeningSystem HardeningMicroservice VulnerabilitiesSupply Chain SecurityMonitoring, Logging, and Runtime Security2025 CKS syllabus with domain weightings:1. Cluster Setup (15%)Use network security policies to restrict accessApply CIS benchmarks to Kubernetes components (e.g., etcd, kubelet)Secure Ingress with TLSProtect node metadata and endpointsVerify platform binaries before deployment2. Cluster Hardening (15%)Implement Role-Based Access Control (RBAC)Manage service accounts securelyRestrict Kubernetes API accessKeep Kubernetes versions up to date3. System Hardening (10%)Minimize host OS footprintApply least-privilege access principlesLimit external network accessUse kernel hardening tools (e.g., AppArmor, seccomp)4. Minimize Microservice Vulnerabilities (20%)Apply pod security standardsManage Kubernetes secrets securelyUse isolation techniques (e.g., sandboxed containers)Implement Pod-to-Pod encryption (e.g., Cilium, Istio)5. Supply Chain Security (20%)Reduce base image sizeUnderstand and secure the software supply chain (e.g., SBOM, CI/CD)Use trusted registries and validate artifactsPerform static analysis (e.g., Kubesec, KubeLinter)6. Monitoring, Logging, and Runtime Security (20%)Detect malicious behavior using analyticsMonitor infrastructure, apps, and workloadsInvestigate attack phases and actorsEnsure container immutability at runtimeUse Kubernetes audit logs effectively

课程标签

0人关注该课程

主题相关的课程