Training > Cloud and Containers > Kubernetes Security Fundamentals (LFS460)
INSTRUCTOR-LED COURSE

Kubernetes Security Fundamentals (LFS460)

Use hands-on labs to learn new skills and knowledge across a range of security best practices for container-based applications & Kubernetes platforms that will make your IT career profile stand out. In this course you learn to maintain security in dynamic, multi-project environments & address security concerns for cloud production environments.

In this live, instructor-led course you will learn with a cohort of fellow IT professionals while gaining key knowledge & skills related to the Certified Kubernetes Security Specialist (CKS) certification exam. Course enrollment includes:
→ FREE CKS exam registration: 12 months to schedule with one retake
→ FREE CKS exam simulator: 2 attempts
→ 12-month access to course materials

Who Is It For

This course is ideal for anyone holding a CKA certification and interested in or responsible for cloud security.
read less read more
What You’ll Learn

This course exposes you to knowledge and skills needed to maintain security in dynamic, multi-project environments. This course addresses security concerns for cloud production environments and covers topics related to the security container supply chain, discussing topics from before a cluster has been configured through deployment, and ongoing, as well as agile use, including where to find ongoing security and vulnerability information. The course includes hands-on labs to build and secure a Kubernetes cluster, as well as monitor and log security events.
read less read more
What It Prepares You For

The course, along with real-world experience and study, will provide the skills and knowledge also tested by the Certified Kubernetes Security Specialist (CKS) exam.
read less read more
Course Outline
Expand All
Collapse All
Introduction
- Linux Foundation
- Linux Foundation Training
- Linux Foundation Certifications
- Linux Foundation Digital Badges
- Laboratory Exercises, Solutions and Resources
- Things Change in Linux and Open Source Projects
- E-Learning Course: LFS260
- Platform Details
Cloud Security Overview
- Multiple Projects
- What is Security?
- Assessment
- Prevention
- Detection
- Reaction
- Classes of Attackers
- Types of Attacks
- Attack Surfaces
- Hardware and Firmware Considerations
- Security Agencies
- Manage External Access
- Labs
Preparing to Install
- Image Supply Chain
- Runtime Sandbox
- Verify Platform Binaries
- Minimize Access to GUI
- Policy Based Control
- Labs
Installing the Cluster
- Update Kubernetes
- Tools to Harden the Kernel
- Kernel Hardening Examples
- Mitigating Kernel Vulnerabilities
- Labs
Securing the kube-apiserver
- Restrict Access to API
- Enable Kube-apiserver Auditing
- Configuring RBAC
- Pod Security Policies
- Minimize IAM Roles
- Protecting etcd
- CIS Benchmark
- Using Service Accounts
- Labs
Networking
- Firewalling Basics
- Network Plugins
- Mitigate Brute Force Login Attempts
- Ingress Objects
- Pod to Pod Encryption
- Restrict Cluster Level Access
- Labs
Workload Considerations
- Minimize Base Image
- Static Analysis of Workloads
- Runtime Analysis of Workloads
- Container Immutability
- Mandatory Access Control
- SELinux
- AppArmor
- Generate AppArmor Profiles
- Labs
Issue Detection
- Understanding Phases of Attack
- Preparation
- Understanding an Attack Progression
- During an Incident
- Handling Incident Aftermath
- Intrusion Detection Systems
- Threat Detection
- Behavioral Analytics
- Labs
Domain Reviews
- Preparing for the Exam
- Labs
Closing and Evaluation Survey
- Evaluation Survey

Reviews
Oct 2022
Good balance of switching between practical and theoretical parts.
Oct 2022
It was new content for me, and the exercises where pretty nice.
Aug 2022
As a newer Kubernetes user, I was able to pick up a lot of new information, and it helped cement topics I had struggled with.
Aug 2022
Helped me examine other parts of the security tool chain I may not have spent time on otherwise.
Aug 2022
Tim is an affable professor, with a great attitude. When labs were more of an "applied learning", rather than following exact directions, the learning was better.