Question 21

Task
Create a NetworkPolicy named pod-access to restrict access to Pod users-service running in namespace dev-team.
Only allow the following Pods to connect to Pod users-service:

Question 22

Enable audit logs in the cluster, To Do so, enable the log backend, and ensure that
1. logs are stored at /var/log/kubernetes/kubernetes-logs.txt.
2. Log files are retained for 5 days.
3. at maximum, a number of 10 old audit logs files are retained.
Edit and extend the basic policy to log:
  • Question 23

    Service is running on port 389 inside the system, find the process-id of the process, and stores the names of all the open-files inside the /candidate/KH77539/files.txt, and also delete the binary.
  • Question 24

    Fix all issues via configuration and restart the affected components to ensure the new setting takes effect.
    Fix all of the following violations that were found against the API server:- a. Ensure that the RotateKubeletServerCertificate argument is set to true.
    b. Ensure that the admission control plugin PodSecurityPolicy is set.
    c. Ensure that the --kubelet-certificate-authority argument is set as appropriate.
    Fix all of the following violations that were found against the Kubelet:- a. Ensure the --anonymous-auth argument is set to false.
    b. Ensure that the --authorization-mode argument is set to Webhook.
    Fix all of the following violations that were found against the ETCD:-
    a. Ensure that the --auto-tls argument is not set to true
    b. Ensure that the --peer-auto-tls argument is not set to true
    Hint: Take the use of Tool Kube-Bench

    Question 25

    Enable audit logs in the cluster, To Do so, enable the log backend, and ensure that
    1. logs are stored at /var/log/kubernetes-logs.txt.
    2. Log files are retained for 12 days.
    3. at maximum, a number of 8 old audit logs files are retained.
    4. set the maximum size before getting rotated to 200MB
    Edit and extend the basic policy to log:
    1. namespaces changes at RequestResponse
    2. Log the request body of secrets changes in the namespace kube-system.
    3. Log all other resources in core and extensions at the Request level.
    4. Log "pods/portforward", "services/proxy" at Metadata level.
    5. Omit the Stage RequestReceived
    All other requests at the Metadata level