CKS Prep is a guided, hands-on path through the security skills used to protect Kubernetes clusters and workloads. Its 45 labs progress through seven stages, from security boundaries and evidence collection to cluster setup, hardening, workload protection, supply-chain controls, audit analysis, and runtime investigation.
Across 181 verified steps, you will run commands, inspect live state, change security controls, test both allowed and denied behavior, and record evidence. Labs are designed for 30–60 minutes each, with 1,860 minutes of listed practice time in total, so you can build skills incrementally before attempting independent exam-style challenges.
What You Will Learn
- Map Kubernetes trust boundaries and collect useful security evidence with
kubectl - Design NetworkPolicy rules that isolate tenants, preserve DNS, and protect sensitive endpoints
- Apply least-privilege RBAC and control ServiceAccount token exposure and API proxy access
- Inspect and reduce host and node risk with kube-bench findings, Linux services, AppArmor, seccomp, and safer storage
- Harden Pods with non-root identities, dropped capabilities, Restricted Pod Security, protected Secrets, and immutable filesystems
- Validate images and release artifacts using minimal builds, KubeLinter, Helm output, checksums, SBOM data, and admission policy
- Investigate bounded audit and runtime evidence, restore deleted controls, and quarantine suspicious workloads
Who This Course Is For
This course is for Kubernetes administrators, platform engineers, DevSecOps practitioners, and CKS candidates who want guided practice before working through assessment-style tasks. The Beginner label reflects the step-by-step treatment of Kubernetes security topics, not an introduction to Kubernetes itself.
Prerequisites: Basic Kubernetes administration, including familiarity with kubectl, YAML, Pods, Deployments, Services, namespaces, and common Linux shell commands. CKA-level knowledge is strongly helpful for CKS preparation, but no LabEx course state or artifacts are required.
Learning environment: Each lab opens in a separate browser-accessible Ubuntu 22.04 VM with a prepared single-node Kubernetes v1.34 environment. Required manifests, images, profiles, certificates, Helm charts, checksums, SBOM records, security findings, and bounded audit data are supplied locally for reproducible practice.
Frequently Asked Questions
How is this course different from the CKS practice exams?
CKS Prep explains the workflow through guided steps, expected observations, commands, and verification. The practice exams present independent final-state challenges with much less guidance, so this course is the better starting point for learning the techniques.
Does “Beginner” mean I can start without Kubernetes experience?
No. The labs introduce security concepts carefully, but they assume you already understand core Kubernetes objects and can use kubectl and YAML. Learners new to Kubernetes should first build basic administration skills.
Will I configure real controls or only study security theory?
You will configure and test live NetworkPolicy, RBAC, Pod Security, AppArmor, seccomp, admission policies, runtime settings, and host permissions. Potentially fragile external systems are represented by controlled local services and staged evidence.
Is completing this course equivalent to earning CKS certification?
No. This is an independent LabEx preparation course and does not award the official CKS certification. It builds practical security skills, while certification eligibility and exam requirements are managed separately by the official provider.




