Hands-on Lab·Certified Kubernetes Security Specialist
Identifying the Phases of an Attack
One compromised Pod, three phases, and then the same three phases from the defender's side. The competency asks you to identify phases of attack, so this guide runs one on a real cluster and looks for it afterwards.
Monitoring and Runtime Guide 36 of 40 Advanced
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 17 min
- Reviewed25 August 2026
Written against the versions above. Cilium 1.18.1 with Hubble, on a cluster with no NetworkPolicy and no audit logging - which is the default state and the reason the trace looks like this.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA6001 | 192.168.0.46 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE01 | 192.168.0.47 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE02 | 192.168.0.48 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
-
The scene
-
Three phases, in order
-
What the network layer saw
-
What the API layer saw, and did not