Skip to main content

Exercises

Reduce host privilege; trigger a sanitizer; inspect mitigations; harden a baseline; test segmentation; capture TLS and DNS; validate proxy headers; enumerate IAM paths; block metadata; harden an image; write RBAC and network policy; test namespace escape assumptions; set quotas; query audit logs; and run containment.

Required evidence

Submit authorized topology, effective policy and reachability, commands and configuration, attack and denial evidence, correlated audit events, containment, regression or policy gate, and residual risk. Redact all credentials and sensitive identifiers.

Oral defense

Trace one path across host, network, cloud, and workload boundaries; identify the first effective control; demonstrate containment and credential revocation; and state the remaining trusted layer.

Source backbone

Use Building Secure and Reliable Systems, NIST SP 800-190, Kubernetes security docs, and official provider documentation.