What this objective tests
CKS Cluster Setup — Key Topics
Apply NetworkPolicies, configure API server admission plugins, secure Ingress with TLS, and run kube-bench. The critical thing: verify your NetworkPolicy actually blocks traffic using kubectl exec between pods.
- Creating NetworkPolicy objects to restrict pod ingress and egress by namespace, label, and port
- Enabling and configuring admission controllers such as NodeRestriction and PodSecurity admission on the API server
- Hardening Ingress with TLS, and restricting access using NetworkPolicy or Ingress annotations
- Running CIS benchmark tooling like kube-bench and remediating control plane and kubelet findings