The blueprint
A mock exam here has 60 questions in 90 minutes, split across the domains in the same proportions as the official exam guide. The official pass mark is 75%. FixOps scores practice against a target of 75%.
-
01
Overview of Cloud Native Security
-
02
Kubernetes Cluster Component Security
-
03
Kubernetes Security Fundamentals
-
04
Kubernetes Threat Model
-
05
Platform Security
-
06
Compliance and Security Frameworks
Sample questions
Three of the 10 questions in the free diagnostic. Open one to see the answer and why.
The 4Cs model describes cloud native security in layers. Which order goes from the outermost layer to the innermost?
- Cloud, Cluster, Container, Code
- Cluster, Cloud, Code, Container
- Code, Container, Cluster, Cloud
- Container, Code, Cloud, Cluster
Answer: Cloud, Cluster, Container, Code. The model nests Code inside the Container, the Container inside the Cluster, and the Cluster inside the Cloud (or the data centre it runs in). Each inner layer relies on the layers around it, which is why the list is read from the outside in.
A company uses a managed Kubernetes service. Under the shared responsibility model, which task normally remains with the company?
- Deciding which users and workloads get which RBAC permissions
- Keeping the provider's data centres physically secure
- Operating and backing up the etcd members of the managed control plane
- Patching the operating system of the control plane hosts
Answer: Deciding which users and workloads get which RBAC permissions. A managed service runs and patches the control plane, including etcd, and secures the facilities. What the customer deploys and who may do what in the cluster (RBAC, network policy, workload settings) stays with the customer.
Why is the API server the most security-critical component of a cluster?
- Every read and change of cluster state passes through it, so it enforces authentication, authorisation and admission
- It assigns IP addresses to pods and programs the packet filtering rules of each node
- It runs the containers of every workload on the control plane host
- It stores cluster state on its own disk and replicates it to every node
Answer: Every read and change of cluster state passes through it, so it enforces authentication, authorisation and admission. Users, controllers and kubelets all work through the API server, and it is the only component that talks to etcd. That makes it the place where identity is checked, permissions are evaluated and admission policy runs. Containers are run by kubelets, state is kept in etcd, and pod networking belongs to the network plugin.
Revision notes: Overview of Cloud Native Security
The notes for one domain, free to read here and in the app. FixOps Pro has them for all 6 domains.
The models used to reason about cloud native security, who secures what under a cloud provider, the kinds of control and isolation available, and how images and application code are kept trustworthy.
The 4Cs and the lifecycle
- The 4Cs are Cloud, Cluster, Container and Code, read from the outermost layer to the innermost.
- Each layer relies on the layers around it, so a weak outer layer undermines everything inside it.
- RBAC, admission control and network policy belong to the Cluster layer; image scanning and security contexts belong to the Container layer.
- The CNCF security whitepaper follows a workload through four phases: Develop, Distribute, Deploy and Runtime.
- Defence in depth means several independent controls, so that one failing does not expose the system.
Cloud provider and infrastructure
- With a managed Kubernetes service the provider runs and patches the control plane, including etcd.
- The customer still decides who may do what (RBAC), what the workloads are allowed to do and which traffic is permitted.
- The instance metadata service can hand a node's cloud credentials to any pod that reaches it, so access from pods is blocked or limited.
- Node identities get only the cloud permissions the node itself needs.
- The API server endpoint is reachable only from the networks that need it; etcd is never exposed.
- Encryption in transit is TLS on the network; encryption at rest covers disks, volumes, backups and the data in etcd.
Controls and principles
- Preventive controls stop an action (an admission policy), detective controls reveal it (an audit log), and corrective controls repair afterwards (a restore).
- Least privilege gives each identity only the access its task requires.
- Zero trust authenticates and authorises every request, wherever it comes from; being inside the network grants nothing.
- The CIS Kubernetes Benchmark is the usual baseline for checking how a cluster is configured.
Isolation techniques
- Linux namespaces give a container its own view of processes, network and mounts; cgroups limit the resources it uses.
- Containers on a node share that node's kernel, which is why kernel flaws and excess privileges matter.
- A Kubernetes namespace scopes names, RBAC, quotas and network policies; by itself it isolates neither the network nor the kernel.
- Sandboxed runtimes such as gVisor (a user-space kernel) and Kata Containers (a lightweight virtual machine per pod) add a stronger boundary and are selected with a RuntimeClass.
- Dedicated nodes are kept for one tenant with taints, tolerations and node selection.
- A cluster per tenant is the strongest isolation; a namespace per tenant shares the control plane and the nodes.
Images, registries and code
- A digest names exact image content; a tag can be moved to different content later.
- Minimal or distroless base images contain fewer packages, so fewer vulnerabilities and fewer tools for an intruder.
- A registry needs authentication, authorisation and vulnerability scanning of what it stores.
- A valid signature shows who produced an image and that it has not changed; it says nothing about vulnerabilities.
- Credentials baked into an image can be read from its layers by anyone who can pull it.
- Software composition analysis finds vulnerable third-party dependencies; static analysis inspects the team's own code.
- Shifting left means finding problems during development and build, in addition to admission and runtime checks.
Easy to mix up
- The 4Cs are layers (Cloud, Cluster, Container, Code); Develop, Distribute, Deploy and Runtime are lifecycle phases.
- A Linux namespace isolates a process; a Kubernetes namespace groups API objects.
- Signing proves origin and integrity; scanning looks for known vulnerabilities.
- Encoding (base64) is reversible by anyone; encryption needs a key.
- gVisor intercepts system calls in user space; Kata Containers gives each pod its own virtual machine.