Hands-on Lab·Certified Kubernetes Security Specialist
Threat Detection Across Cluster Layers
The competency asks you to detect threats across infrastructure, apps, networks, data and users. This guide does one small thing to a cluster and then hunts for it from every vantage point that exists, which is the fastest way to learn what each layer is for.
Monitoring and Runtime Guide 37 of 40 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 15 min
- Reviewed25 August 2026
Written against the versions above. containerd 2.2.6 and the kubelet's own log layout on disk. Nothing here needs a tool that is not already on the node.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA6001 | 192.168.0.46 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE01 | 192.168.0.47 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE02 | 192.168.0.48 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 36 - the same question asked about a whole attack.
-
One action, then go looking for it
-
The Kubernetes layer, and the workload layer
-
The runtime layer
-
The scoreboard