Exam CKS Topic 5 Question 34 Discussion

Actual exam question for Linux Foundation's CKS exam
Question #: 34
Topic #: 5
You need to implement a secure CI/CD pipeline for building and deploying containerized applications to a Kubemetes cluster. The pipeline should include security checks and validation steps at each stage to minimize the risk of introducing vulnerabilities. What security best practices would you follow?

Suggested Answer:

Solution (Step by Step) :
1. Source Code Security:
- Static Application Security Testing (SAST): Integrate SAST tools into your CIICD pipeline to identify vulnerabilities in your source code.
- Dependency Scanning: Use dependency scanning tools to identify known vulnerabilities in your application's dependencies.
- Code Review: Enforce mandatory code reviews for all changes to production branches to catch potential vulnerabilities.
2. Container Image Security'
- Container Image Scanning: Scan your container images for vulnerabilities and malware.
- Multi-stage Builds: Use multi-stage Docker builds to create smaller and more secure container images.
- Signed Images: Sign your container images to ensure their authenticity and prevent tampering.
3. Infrastructure Security:
- Infrastructure as Code (IaC): Use Iac tools to define your Kubernetes infrastructure and configurations, ensuring consistency and security.
- Policy Enforcement: Implement Kubernetes admission controllers and policies to enforce security best practices during deployment.
4. Deployment Security:
- Role-Based Access Control (RBAC): Use RBAC to restrict access to sensitive Kubernetes resources.
- Network Policies: Implement network policies to control communication between pods.
- Deployment Strategies: Choose deployment strategies like rolling updates or canary deployments to minimize the impact of security incidents.
5. Monitoring and Auditing:
- Kubernetes Logging and Monitoring: Configure logging and monitoring to track events and identify potential security incidents.
- Security Auditing: Regularly audit your CI/CD pipeline and Kubernetes cluster for security compliance.
6. Continuous Security Assessment:
- Security Scanning: Regularly scan your source code, container images, and infrastructure for vulnerabilities.
- Vulnerability Management Track and remediate discovered vulnerabilities.
7. Secure Development Practices:
- Secure Coding Standards: Enforce secure coding standards and best practices.
- Security Training: Provide security training to developers to increase awareness of common vulnerabilities.
- Security Bug Bounties: Consider offering security bug bounties to incentivize ethical hackers to find and report vulnerabilities.

by Vic at Mar 31, 2026, 10:43 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10