Kubernetes and Cloud Native Security Associate
<strong>Cluster Component Security (22 %)</strong> walks the components one by one — API server, controller manager, scheduler, kubelet, container runtime, kube-proxy, Pod, etcd, container networking, client security and storage. <strong>Security Fundamentals (22 %)</strong> is Pod Security Standards and Admission, authentication and authorization, Secrets, isolation and segmentation, audit logging and network policy. <strong>Threat Model (16 %)</strong> covers trust boundaries and data flow, persistence, denial of service, malicious code execution, an attacker on the network, access to sensitive data and privilege escalation. <strong>Platform Security (16 %)</strong> is supply chain, image repositories, observability, service mesh, PKI, connectivity and admission control. <strong>Overview (14 %)</strong> is the 4Cs, cloud and infrastructure security, controls and frameworks, isolation techniques, artifact and image security. <strong>Compliance (10 %)</strong> is compliance and threat-modelling frameworks, supply chain compliance, and automation.
Choose this if…
- You run clusters and want the security model named rather than absorbed by osmosis
- You are heading for CKS and want the concepts before the terminal
- You are a security engineer meeting Kubernetes as one more system to assess
