CKS Preparation
Workshop

A four-day workshop specifically designed to prepare you for the Certified Kubernetes Security Specialist (CKS) exam, covering all six exam domains of Kubernetes security hands-on: cluster hardening with kube-bench, image signing with Cosign, vulnerability scanning with Trivy, and runtime monitoring with Falco. From foundational concepts through supply chain security and runtime security, you’ll learn how to effectively secure Kubernetes clusters and applications. The course covers essential areas such as network policies, access control (RBAC), secrets management, and Kubernetes auditing. You

Made in Germany ISO 27001 ISO 9001 DSGVO-konform DORA Compliant 24/7 Support
UDSVolkswagenLiebherrT-SystemsVendureecoConnextPortainerBITMARCKUelzener VersicherungenFJDDWTOCCReiner SCTCyrus IndustrialDGSIEMnanocosmosInheadenSplixSchwarzgruppeINHHadesHiOrg-Serverown3dTikfinityProgram51Buben & MädchenPrime InsightsTELTECElevantiqMoovitCFToolsStadt KölnVivavisAvemio

Workshop overview

Duration, per-participant price and logistics for CKS Preparation.

On-site options

  • Live online or on-site at your location

  • In-house: content, duration and focus can be tailored

  • Flexible dates, from 1 participant

  • German; English on request

  • Preconfigured cloud lab (also on-site)

  • Open groups: max. 8 people

  • Seat price same as online: €721.50 × days, excl. VAT

  • On-site in-house: individual quote (travel/logistics as incurred)

  • No published flat on-site surcharge

  • You provide the training room and internet

  • Open sessions: 09:00–16:00 (CET/CEST)

Curriculum

Topics by day at a glance.

Day 1: Cluster architecture, CIS benchmarks, and RBAC hardening

  • Kubernetes Security Architecture: Control Plane and Data Plane
  • CIS Benchmarks: Securing API Server, etcd, and Kubelet
  • RBAC & Access Control: Enforce Least Privilege
  • Node Hardening: Kernel Security with AppArmor and seccomp
Day 1

Day 2: Pod security, secrets management, and network security

  • Pod Security Standards (PSS) and Container Isolation
  • Secrets Management & Pod Security Context: etcd Encryption and Non-Root Containers
  • Network Policies: Default Deny and Micro-Segmentation
  • Secure Ingress & Gateway API with TLS: Protect External Traffic
Day 2

Day 3: Supply chain security and runtime monitoring

  • Supply Chain Security: SBOM, Image Signing, and Admission Control
  • Image Scanning & Manifest Validation: CVE Detection with Trivy
  • API Server Authentication: OIDC Integration and Webhook Token Auth
  • Runtime Threat Detection with Falco: Detect Anomalies in Real-Time
Day 3

Day 4: Audit logs, forensics, and CKS exam preparation

  • Kubernetes Audit Logs: Track and Analyze Critical Events
  • Incident Response: Isolate and Analyze Compromised Pods
  • Cluster Forensics: Reconstruct Attack Vectors and Find Root Cause
  • Review & CKS Exam Prep: Time Management and Pitfalls
  • Conclusion & Q&A: Options After Passing the Exam
Day 4

Workshop schedule

Published daily rhythm. Topics are listed in the curriculum.

09:00–16:00 (CET/CEST)

Official window for open sessions.

Frame

09:00 – Introductions

On day 1: meet the instructor and participants, plus the agenda and workshop structure.

Day 1

09:00 – Q&A

On later days, resolve open questions from the previous day before the day’s topics (usually 09:00–09:30 or 09:00–10:00).

Later days

Content blocks follow the curriculum

Theory and hands-on in the morning and afternoon blocks. The topic list is in the curriculum above.

Topics

12:00–13:00 – Lunch

A shared break before the afternoon.

Break

16:00–16:30 – Q&A

End of the day: questions, exchange and wrap-up.

Close

Prerequisites

What participants should bring.

Hardware

Your own notebook (Linux, macOS or Windows) with permission to install software. Devices available at extra cost.

HardwareNotebook

Environment

Each participant works in a provided cloud lab. Local installation of the training stack is not required.

LabCloud

Prerequisites

Basic Linux/terminal skills are helpful.

Prerequisites

Related workshops

Suggested follow-on courses from the catalog.

Introduction to Kyverno

  • Duration: 3 days