All courses

Advanced container security

The security capstone. Build a container by hand from namespaces and cgroups so the boundary is concrete, then secure the supply chain with minimal images, SBOMs, scanning, signing and promotion by digest. Harden the container with non-root users, read-only filesystems, capabilities, seccomp and AppArmor, then the daemon and host with rootless mode, socket controls and user namespaces. It ends with network and runtime hardening, forensics, escape paths, and the sandboxes and detection that close them. Twenty-four lessons across six sections, with defensive labs on Docker Engine 29.8.2.

Advanced6 sections · 24 lessons · ~7h total · 41-question self-test

Progress is saved in this browser only — no account required.

Quick reference

Final exam
Test yourself on everything
41 questions drawn from all 6 sections — every answer explained as you pick.
Start final exam