CKS Prep

July 1, 2026 · View on GitHub

Languages: English · 简体中文 · Español · Français · Deutsch · 日本語 · Русский · 한국어 · Português

CKS Prep

A guided Certified Kubernetes Security Specialist (CKS) preparation course with 45 Kubernetes security labs arranged from security foundations to cluster setup, hardening, workload security, supply chain, audit, and runtime investigation.

Start Course on LabEx

Exercises

IndexNameDifficultyPractice
01Map Kubernetes Security BoundariesBeginnerStart Lab
02Collect Security Evidence with kubectlBeginnerStart Lab
03Review Namespaces and Tenant IsolationBeginnerStart Lab
04Inspect RBAC Subjects and PermissionsBeginnerStart Lab
05Inspect ServiceAccount Token BehaviorBeginnerStart Lab
06Apply Pod Security StandardsBeginnerStart Lab
07Restrict Namespace Traffic with NetworkPolicyBeginnerStart Lab
08Allow DNS Through Default-Deny EgressBeginnerStart Lab
09Publish Ingress with TLSBeginnerStart Lab
10Deny Workload Access to Node MetadataBeginnerStart Lab
11Verify Kubernetes BinariesBeginnerStart Lab
12Review CIS Findings with kube-benchBeginnerStart Lab
13Check Admission and Pod Security ReadinessBeginnerStart Lab
14Minimize a Role's PermissionsBeginnerStart Lab
15Reduce an Overprivileged ClusterRoleBindingBeginnerStart Lab
16Disable Default ServiceAccount Token MountsBeginnerStart Lab
17Scope a Namespace Operator RoleBeginnerStart Lab
18Block API Server Proxy EscalationBeginnerStart Lab
19Contain a Leaked ServiceAccount TokenBeginnerStart Lab
20Audit Access to Sensitive ResourcesBeginnerStart Lab
21Inspect Host Attack Surface SafelyBeginnerStart Lab
22Disable a Host Debug ServiceBeginnerStart Lab
23Review kubelet ExposureBeginnerStart Lab
24Review AppArmor Profile Enforcement on a WorkloadBeginnerStart Lab
25Install a Local seccomp ProfileBeginnerStart Lab
26Remove HostPath Access from a WorkloadBeginnerStart Lab
27Harden a Pod Security ContextBeginnerStart Lab
28Drop Linux CapabilitiesBeginnerStart Lab
29Run Containers as Non-RootBeginnerStart Lab
30Protect Secrets with Projected FilesBeginnerStart Lab
31Rotate and Constrain Application SecretsBeginnerStart Lab
32Isolate a Risky Sidecar BoundaryBeginnerStart Lab
33Enforce Immutable Runtime ContainersBeginnerStart Lab
34Quarantine a Suspicious WorkloadBeginnerStart Lab
35Build a Minimal Approved ImageBeginnerStart Lab
36Scan Workload Manifests with kube-linterBeginnerStart Lab
37Scan Helm Output with kube-linterBeginnerStart Lab
38Verify SBOM and Checksum EvidenceBeginnerStart Lab
39Enforce Trusted Image RegistriesBeginnerStart Lab
40Remove Build Secrets from an ImageBeginnerStart Lab
41Review Audit Events for Secret AccessBeginnerStart Lab
42Investigate Unauthorized API ActivityBeginnerStart Lab
43Detect Suspicious Runtime ProcessesBeginnerStart Lab
44Detect Runtime File DriftBeginnerStart Lab
45Restore Policy from Audit EvidenceBeginnerStart Lab

About LabEx

LabEx is a hands-on learning platform for beginners.

Explore Linux, DevOps, Cybersecurity, and more — all directly in your browser.

Learn step by step through interactive labs, guided exercises, and real-world projects. 🌱
No setup, no stress — just practice and grow your skills by doing.


Download on the App Store Download on the Mac App Store


📖 Need help? Visit our Help Center or email info@labex.io