Back to Practice
Challenge

Secure a Workload

Exam-pace drill: give a workload a scoped identity (ServiceAccount + RBAC), lock the container down, and isolate it with a NetworkPolicy — exact specs, costly hints, tight timer.

Your mission

A drill, not a tutorial: exam-paced, exact specs, hints cost real points. Work in the secure namespace (already created). Aim to finish without opening a hint.

You'll give a workload a scoped identity, run it locked down, and fence it off on the network — three security disciplines the exam expects you to combine quickly and correctly.

kubectl config set-context --current --namespace=secure

Skills you'll put into practice

ckadexam-drillsecurity

Make it your own.

Use this topic as a starting point for a fresh custom scenario.

Create a variation