The Attack 0806
Course Content
0 / 85 completedExam Information 0147
Course Introduction 0855
The 4C’s of Cloud Native security 0313
The Attack 0806
Section Introduction 0115
What are CIS Benchmarks 0552
CIS benchmark for Kubernetes 0241
Kubebench 0115
Kubernetes Security Primitives 0318
TLS Introduction 0128
Authentication 0534
Service Accounts 1434
TLS in Kubernetes 0748
TLS Basics 2003
TLS in Kubernetes – Certificate Creation 1055
View Certificate Details 0431
Certificates API 0607
API Groups 0552
KubeConfig 0832
RBAC 0428
Authorization 0730
Cluster Roles and Role Bindings 0433
Kubelet Security 1448
Kubectl Proxy Port Forward 0648
Kubernetes Dashboard 0613
Securing Kubernetes Dashboard 0138
Kubernetes Software Versions 0254
Verify platform binaries before deploying 0211
Cluster Upgrade Process 1111
Network Policy 0751
Developing Network Policies 1136
Docker Service Configuration 0657
Docker – Securing the Daemon 0725
Demo – Cluster Upgrade 1137
Ingress 2234
Section Introduction 0130
Minimize host OS footprint Intro 0051
Least Privilege Principle 0516
Limit Node Access 0548
SSH Hardening 0549
Privilege Escalation in Linux 0305
Remove Obsolete Packages and Services 0256
Restrict Kernel Modules 0231
Identify and Disable Open Ports 0221
Minimize IAM roles 0546
Minimize external access to the network 0212
UFW Firewall Basics 0555
Linux Syscalls 0420
AquaSec Tracee 0320
Restrict syscalls using seccomp 0837
AppArmor 0409
Implement Seccomp in Kubernetes 0751
Linux Capabilities 0405
AppArmor in Kubernetes 0244
Creating AppArmor Profiles 0511
Section Introduction 0054
Security Contexts 0152
Admission Controllers 0807
Validating and Mutating Admission Controllers 1026
Open Policy Agent OPA 0948
Pod Security Policies Optional 0739
OPA in Kubernetes 0945
Container Sandboxing 0653
Manage Kubernetes secrets 0820
gVisor 0455
Runtime Classes 0317
kata Containers 0225
Using Runtimes in Kubernetes 0223
Demo Encrypting Secret Data at Rest 1847
One way SSL vs Mutual SSL 0437
Implement pod to pod encryption by use of mTLS 0635
Section Introduction 0030
Image Security 0443
Minimize base image footprint 0724
Use static analysis of user workloads egKubernetes resources Docker files 0246
Whitelist Allowed Registries – Image Policy Webhook 0516
Scan images for known vulnerabilities Trivy 0834
Section Introduction 0050
Perform behavioral analytics of syscall process 0447
Falco Overview and Installation 0253
Use Falco to Detect Threats 0839
Falco Configuration Files 0654
Ensure Immutability of Containers at Runtime 0518
Mutable vs Immutable Infrastructure 0450
Use Audit Logs to monitor access 1018