Course Code: lfs460
Duration: 28 hours
Prerequisites:

Participants should have an understanding of Linux administration skills, comfortable using the command line. Must be able to edit files using a command-line text editor. Basic security knowledge.

Audience

This course is ideal for anyone holding a CKA certification and interested in or responsible for cloud security.

Experience Level: Intermediate

Overview:

This instructor-led course provides skills and knowledge across a broad range of best practices for securing container-based applications and Kubernetes platforms during build, deployment, and runtime.

What you will learn?

This course exposes you to knowledge and skills needed to maintain security in dynamic, multi-project environments.

This course addresses security concerns for:

  • cloud production environments
  • covers topics related to the security container supply chain,
  • topics from before a cluster has been configured through deployment, and ongoing,
  • agile use, including where to find ongoing security and vulnerability information.

The course includes hands-on labs to build and secure a Kubernetes cluster, as well as monitor and log security events.

What you will gain?

This course is designed as preparation for the Certified Kubernetes Security Specialist (CKS) exam and will substantially increase students’ ability to become certified.

Course Outline:

Introduction

  • Linux Foundation
  • Linux Foundation Training
  • Linux Foundation Certifications
  • Linux Foundation Digital Badges
  • Laboratory Exercises, Solutions and Resources
  • E-Learning Course: LFS260
  • Distribution Details
  • Labs

Cloud Security Overview

  • Multiple Projects
  • What is Security?
  • Assessment
  • Prevention
  • Detection
  • Reaction
  • Classes of Attackers
  • Types of Attacks
  • Attack Surfaces
  • Hardware and Firmware Considerations
  • Security Agencies
  • Manage External Access
  • Labs

Preparing to Install

  • Image Supply Chain
  • Runtime Sandbox
  • Verify Platform Binaries
  • Minimize Access to GUI
  • Policy Based Control
  • Labs

Installing the Cluster

  • Update Kubernetes
  • Tools to Harden the Kernel
  • Kernel Hardening Examples
  • Mitigating Kernel Vulnerabilities
  • Labs

Securing the kube-apiserver

  • Restrict Access to API
  • Enable Kube-apiserver Auditing
  • Configuring RBAC
  • Pod Security Policies
  • Minimize IAM Roles
  • Protecting etcd
  • CIS Benchmark
  • Using Service Accounts
  • Labs

Networking

  • Firewalling Basics
  • Network Plugins
  • iptables
  • Mitigate Brute Force Login Attempts
  • Netfilter rule management
  • Netfilter Implementation
  • nft Concepts
  • Ingress Objects
  • Pod to Pod Encryption
  • Restrict Cluster Level Access
  • Labs

Workload Considerations

  • Minimize Base Image
  • Static Analysis of Workloads
  • Runtime Analysis of Workloads
  • Container Immutability
  • Mandatory Access Control
  • SELinux
  • AppArmor
  • Generate AppArmor Profiles
  • Labs

Issue Detection

  • Understanding Phases of Attack
  • Preparation
  • Understanding an Attack Progression
  • During an Incident
  • Handling Incident Aftermath
  • Intrusion Detection Systems
  • Threat Detection
  • Behavioral Analytics
  • Labs

Domain Reviews

  • Preparing for the Exam - CKS
Sites Published:

United Arab Emirates - Kubernetes Security Fundamentals (LFS460)

Qatar - Kubernetes Security Fundamentals (LFS460)

Egypt - Kubernetes Security Fundamentals (LFS460)

Saudi Arabia - Kubernetes Security Fundamentals (LFS460)

South Africa - Kubernetes Security Fundamentals (LFS460)

Brasil - Kubernetes Security Fundamentals (LFS460)

Canada - Kubernetes Security Fundamentals (LFS460)

中国 - Kubernetes Security Fundamentals (LFS460)

香港 - Kubernetes Security Fundamentals (LFS460)

澳門 - Kubernetes Security Fundamentals (LFS460)

台灣 - Kubernetes Security Fundamentals (LFS460)

USA - Kubernetes Security Fundamentals (LFS460)

Österreich - Kubernetes Security Fundamentals (LFS460)

Schweiz - Kubernetes Security Fundamentals (LFS460)

Deutschland - Kubernetes Security Fundamentals (LFS460)

Czech Republic - Kubernetes Security Fundamentals (LFS460)

Denmark - Kubernetes Security Fundamentals (LFS460)

Estonia - Kubernetes Security Fundamentals (LFS460)

Finland - Kubernetes Security Fundamentals (LFS460)

Greece - Kubernetes Security Fundamentals (LFS460)

Magyarország - Kubernetes Security Fundamentals (LFS460)

Ireland - Kubernetes Security Fundamentals (LFS460)

Luxembourg - Kubernetes Security Fundamentals (LFS460)

Latvia - Kubernetes Security Fundamentals (LFS460)

España - Kubernetes Security Fundamentals (LFS460)

Italia - Kubernetes Security Fundamentals (LFS460)

Lithuania - Kubernetes Security Fundamentals (LFS460)

Nederland - Kubernetes Security Fundamentals (LFS460)

Norway - Kubernetes Security Fundamentals (LFS460)

Portugal - Kubernetes Security Fundamentals (LFS460)

România - Kubernetes Security Fundamentals (LFS460)

Sverige - Kubernetes Security Fundamentals (LFS460)

Türkiye - Kubernetes Security Fundamentals (LFS460)

Malta - Kubernetes Security Fundamentals (LFS460)

Belgique - Kubernetes Security Fundamentals (LFS460)

France - Kubernetes Security Fundamentals (LFS460)

日本 - Kubernetes Security Fundamentals (LFS460)

Australia - Kubernetes Security Fundamentals (LFS460)

Malaysia - Kubernetes Security Fundamentals (LFS460)

New Zealand - Kubernetes Security Fundamentals (LFS460)

Philippines - Kubernetes Security Fundamentals (LFS460)

Singapore - Kubernetes Security Fundamentals (LFS460)

Thailand - Kubernetes Security Fundamentals (LFS460)

Vietnam - Kubernetes Security Fundamentals (LFS460)

India - Kubernetes Security Fundamentals (LFS460)

Argentina - Kubernetes Security Fundamentals (LFS460)

Chile - Kubernetes Security Fundamentals (LFS460)

Costa Rica - Kubernetes Security Fundamentals (LFS460)

Ecuador - Kubernetes Security Fundamentals (LFS460)

Guatemala - Kubernetes Security Fundamentals (LFS460)

Colombia - Kubernetes Security Fundamentals (LFS460)

México - Kubernetes Security Fundamentals (LFS460)

Panama - Kubernetes Security Fundamentals (LFS460)

Peru - Kubernetes Security Fundamentals (LFS460)

Uruguay - Kubernetes Security Fundamentals (LFS460)

Venezuela - Kubernetes Security Fundamentals (LFS460)

Polska - Kubernetes Security Fundamentals (LFS460)

United Kingdom - Kubernetes Security Fundamentals (LFS460)

South Korea - Kubernetes Security Fundamentals (LFS460)

Pakistan - Kubernetes Security Fundamentals (LFS460)

Sri Lanka - Kubernetes Security Fundamentals (LFS460)

Bulgaria - Kubernetes Security Fundamentals (LFS460)

Bolivia - Kubernetes Security Fundamentals (LFS460)

Indonesia - Kubernetes Security Fundamentals (LFS460)

Kazakhstan - Kubernetes Security Fundamentals (LFS460)

Moldova - Kubernetes Security Fundamentals (LFS460)

Morocco - Kubernetes Security Fundamentals (LFS460)

Tunisia - Kubernetes Security Fundamentals (LFS460)

Kuwait - Kubernetes Security Fundamentals (LFS460)

Oman - Kubernetes Security Fundamentals (LFS460)

Slovakia - Kubernetes Security Fundamentals (LFS460)

Kenya - Kubernetes Security Fundamentals (LFS460)

Nigeria - Kubernetes Security Fundamentals (LFS460)

Botswana - Kubernetes Security Fundamentals (LFS460)

Slovenia - Kubernetes Security Fundamentals (LFS460)

Croatia - Kubernetes Security Fundamentals (LFS460)

Serbia - Kubernetes Security Fundamentals (LFS460)

Bhutan - Kubernetes Security Fundamentals (LFS460)

Nepal - Kubernetes Security Fundamentals (LFS460)

Uzbekistan - Kubernetes Security Fundamentals (LFS460)