All courses

Runtime & eBPF security

What a container actually does at execution time, and how to see and stop the bad parts: eBPF and the kernel security model, seccomp/AppArmor/SELinux and capability hardening, Falco detection and tuning, Tetragon and Cilium in-kernel enforcement, and container-escape techniques with detection and a runtime incident-response runbook.

Advanced5 sections · 15 lessons · ~9h total · 60-question self-test

Progress is saved in this browser only — no account required.

Final exam
Test yourself on everything
60 questions drawn from all 5 sections — every answer explained as you pick.
Start final exam