Question 26

SIMULATION
Given an existing Pod named test-web-pod running in the namespace test-system Edit the existing Role bound to the Pod's Service Account named sa-backend to only allow performing get operations on endpoints.
Create a new Role named test-system-role-2 in the namespace test-system, which can perform patch operations, on resources of type statefulsets.
Create a new RoleBinding named test-system-role-2-binding binding the newly created Role to the Pod's ServiceAccount sa-backend.
  • Question 27

    Using the runtime detection tool Falco, Analyse the container behavior for at least 30 seconds, using filters that detect newly spawning and executing processes
  • Question 28

    Secrets stored in the etcd is not secure at rest, you can use the etcdctl command utility to find the secret value for e.g:- ETCDCTL_API=3 etcdctl get /registry/secrets/default/cks-secret --cacert="ca.crt" --cert="server.crt" --key="server.key" Output

    Using the Encryption Configuration, Create the manifest, which secures the resource secrets using the provider AES-CBC and identity, to encrypt the secret-data at rest and ensure all secrets are encrypted with the new configuration.

    Question 29

    Service is running on port 389 inside the system, find the process-id of the process, and stores the names of all the open-files inside the /candidate/KH77539/files.txt, and also delete the binary.
  • Question 30

    SIMULATION
    On the Cluster worker node, enforce the prepared AppArmor profile
    #include <tunables/global>
    profile nginx-deny flags=(attach_disconnected) {
    #include <abstractions/base>
    file,
    # Deny all file writes.
    deny /** w,
    }
    EOF'
    Edit the prepared manifest file to include the AppArmor profile.
    apiVersion: v1
    kind: Pod
    metadata:
    name: apparmor-pod
    spec:
    containers:
    - name: apparmor-pod
    image: nginx
    Finally, apply the manifests files and create the Pod specified on it.
    Verify: Try to make a file inside the directory which is restricted.