---
title: "CKS Exam 2026: Study Guide, Practice Labs and Five-Week Plan"
description: "Map every CKS 2026 exam domain, build a kubeadm practice lab, drill Trivy, Falco, AppArmor, and RBAC, then follow a five-week plan to a passing score."
canonical: "https://adamtheautomator.com/cks-certification-study-guide/"
---

# CKS Exam 2026: Study Guide, Practice Labs and Five-Week Plan

> Map every CKS 2026 exam domain, build a kubeadm practice lab, drill Trivy, Falco, AppArmor, and RBAC, then follow a five-week plan to a passing score.

Source: https://adamtheautomator.com/cks-certification-study-guide/

---

ATA Learning

Tap to hide

[

ATA Learning

](/)

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Search for:  

*   [](https://twitter.com/adbertram)
*   [](https://github.com/Adam-the-Automator)
*   [](https://www.linkedin.com/company/adam-the-automator-llc)
*   [](/feed/)

![CKS Exam 2026: Study Guide, Practice Labs and Five-Week Plan](https://adamtheautomator.com/wp-content/uploads/publisher/3ec5d9c85b2b812da7abf2b9778c798e/8e7898c657638b870c388cf9b2e1ea1b99cfd5da6356984d5c703b14d7a098c8.webp)

# CKS Exam 2026: Study Guide, Practice Labs and Five-Week Plan

[![](https://secure.gravatar.com/avatar/d0b9d42e21e5622713f8b693aa5c0f9244d5f7dd200ed29b8398f52dee5de337?s=192&d=mm&r=g)Adam Bertram](https://adamtheautomator.com/author/adam-bertram/)8 October 202611 min. read

Categories: [Information Security](/category/infosec/)

Tags:[Kubernetes](/tag/kubernetes/)[Security](/tag/security/)[Containers](/tag/containers/)[Linux](/tag/linux/)

Table of Contents

*   [What the CKS Exam Actually Tests in 2026](#what-the-cks-exam-actually-tests-in-2026)
*   [The Three Weights That Decide Your Score](#the-three-weights-that-decide-your-score)
*   [Prerequisites: Your CKA Has to Count](#prerequisites-your-cka-has-to-count)
*   [Confirm Your Eligibility Before You Pay](#confirm-your-eligibility-before-you-pay)
*   [Exam Format, Pass Mark, and Blueprint Version](#exam-format-pass-mark-and-blueprint-version)
*   [Which Kubernetes Version the 2026 Exam Runs](#which-kubernetes-version-the-2026-exam-runs)
*   [What the Exam Environment Gives You](#what-the-exam-environment-gives-you)
*   [The Six CKS Domains, Weighted](#the-six-cks-domains-weighted)
*   [A Default-Deny NetworkPolicy You Will Reuse](#a-default-deny-networkpolicy-you-will-reuse)
*   [Hands-On Lab Setup for CKS Practice](#hands-on-lab-setup-for-cks-practice)
*   [Build a Cluster You Are Allowed to Break](#build-a-cluster-you-are-allowed-to-break)
*   [The Security Tools You Have to Operate](#the-security-tools-you-have-to-operate)
*   [Scan an Image and Act on the Result](#scan-an-image-and-act-on-the-result)
*   [Patch an Insecure Pod Spec](#patch-an-insecure-pod-spec)
*   [Enforce the Baseline at the Namespace](#enforce-the-baseline-at-the-namespace)
*   [A Five-Week CKS Study Plan](#a-five-week-cks-study-plan)
*   [Exam-Day Strategy and Time Management](#exam-day-strategy-and-time-management)
*   [Use the Documentation, Do Not Read It](#use-the-documentation-do-not-read-it)
*   [Most-Failed Topics and How to Avoid Them](#most-failed-topics-and-how-to-avoid-them)
*   [The Scenario That Breaks a Running Workload](#the-scenario-that-breaks-a-running-workload)
*   [CKS Certification Cost, Retakes, and Whether It Is Worth Renewing in 2026](#cks-certification-cost-retakes-and-whether-it-is-worth-renewing-in-2026)
*   [The June 2026 Rule in One Line](#the-june-2026-rule-in-one-line)
*   [Frequently Asked Questions](#frequently-asked-questions)
*   [Is the CKS harder than the CKA?](#is-the-cks-harder-than-the-cka)
*   [Can I pass without hands-on practice?](#can-i-pass-without-hands-on-practice)
*   [How long is the CKS valid?](#how-long-is-the-cks-valid)
*   [How many attempts do I get?](#how-many-attempts-do-i-get)
*   [Where to Start This Week](#where-to-start-this-week)

How do you prove you can defend a Kubernetes cluster when the exam hands you a live terminal, a ticking clock, and no multiple-choice fallback? The [Certified Kubernetes Security Specialist (CKS)](https://www.anrdoezrs.net/links/7627660/type/dlg/sid/ata-cks-pluralsight-cks-path/https://www.pluralsight.com/paths/certified-kubernetes-security-specialist-cks) answers with 15 to 20 performance tasks you solve on a running cluster in 120 minutes, and the Linux Foundation [describes the format in one sentence](https://training.linuxfoundation.org/certification/certified-kubernetes-security-specialist/): “The exam is online, proctored, performance-based test that requires solving multiple tasks from a command line running Kubernetes.” If you are sizing up the CKS for 2026, three questions decide the work ahead: what the exam now covers, which labs build real muscle memory, and whether one pass can keep your entire [Kubernetes certification stack](https://adamtheautomator.com/cloud-security-engineer-guide-salary-certs-roadmap/) alive.

This guide answers those questions in the order you will meet them. You start by confirming your CKA still qualifies you to register, then map the six weighted domains. From there you stand up a disposable practice cluster and drill the tools that show up on the exam jump host. The guide closes with a five-week plan that lands on exam day. So what does the exam actually test, and who gets to register? Work the sections in order, and each one hands you the command, manifest, or decision the next question depends on.

## What the CKS Exam Actually Tests in 2026

The CKS is a specialization. It assumes you can already operate a cluster and tests whether you can lock one down across build, deploy, and runtime. The Linux Foundation and the Cloud Native Computing Foundation (CNCF) issue the credential, and it stays [vendor-neutral by design](https://www.cncf.io/), so you solve the same problems whether your clusters run on EKS, AKS, GKE, or bare metal.

What separates the CKS from a multiple-choice security exam is that each task produces an artifact a grader can inspect. You write a NetworkPolicy, patch a kubelet flag, load an AppArmor profile, or edit a Falco rule. A correct answer is a cluster in a specific state, plus a command that proves the state changed.

### The Three Weights That Decide Your Score

Microservice Vulnerabilities, Supply Chain Security, and Monitoring, Logging, and Runtime Security each carry 20% of the score, so 60% of your result sits in three domains. Cluster Setup and Cluster Hardening carry 15% each, and System Hardening carries 10%. That split tells you where study hours pay best: a candidate who owns Pod Security Standards, image scanning, and [runtime detection](https://adamtheautomator.com/practical-guide-kubernetes-security-management/) is already defending a passing score.

* * *

_**Key Insight: The exam rewards configuration you can verify. If you cannot run a command that proves your change took effect, the task is not finished.**_

* * *

Settle the domain map later. First confirm the exam will let you register at all.

## Prerequisites: Your CKA Has to Count

You cannot book the CKS without the Certified Kubernetes Administrator (CKA). The Linux Foundation [states the rule directly](https://training.linuxfoundation.org/certification/certified-kubernetes-security-specialist/): “Certified Kubernetes Security Specialist (CKS) candidates must have taken and passed the Certified Kubernetes Administrator (CKA) exam prior to attempting the CKS exam.” Verify that requirement first, because a lapsed CKA used to force a full retake before you could sit the CKS.

The CNCF relaxed that in 2024, as the [Linux Foundation documented](https://training.linuxfoundation.org/blog/now-updated-cks-exam). You can schedule the CKS if you have achieved the CKA at any point, whether that credential is active, renewed, or already expired. The [Linux Foundation certification FAQ](https://docs.linuxfoundation.org/tc-docs/certification/faq-cka-ckad-cks) carries the current wording, and the registration portal enforces it.

### Confirm Your Eligibility Before You Pay

1.  Sign in to the Linux Foundation training portal and open the CKA entry under your certifications.
    
2.  Confirm the status reads Achieved, Renewed, or Expired, not “Never earned.”
    
3.  If the CKA is missing entirely, schedule the CKA before the CKS.
    

If your study material still insists you hold an active CKA, it predates the 2024 change. Trust the portal over the PDF.

## Exam Format, Pass Mark, and Blueprint Version

The exam runs two hours against a live cluster, with a 67% pass mark. You solve roughly 15 to 20 tasks, and a partial task usually earns partial credit, so a stuck scenario should not stall the rest of the run. The [Linux Foundation important instructions page](https://docs.linuxfoundation.org/tc-docs/certification/important-instructions-cks) spells out the environment rules, and it is worth reading twice before exam week.

### Which Kubernetes Version the 2026 Exam Runs

The CKS tracks current Kubernetes minor releases instead of freezing one version. Current Linux Foundation materials list the exam on Kubernetes v1.34 and v1.35, and a guide still citing v1.30 or earlier describes a retired blueprint. Before you buy study material, open the [Kubernetes releases page](https://kubernetes.io/releases/) and confirm the version your course targets.

### What the Exam Environment Gives You

| Item | Detail |
| --- | --- |
| Time | 120 minutes |
| Tasks | 15 to 20 performance tasks |
| Pass mark | 67% |
| Format | Remote, proctored, terminal only |
| Base node | XFCE desktop host with a terminal and Firefox |
| Retake | One free retake inside 12 months |

Those values reflect the current Linux Foundation materials. Confirm them against your own exam voucher, because pricing and retake terms move.

You reach the simulated clusters over SSH from a base node, and that base node must never be rebooted, because a reboot ends the session.

## The Six CKS Domains, Weighted

The [official domain list](https://training.linuxfoundation.org/certification/certified-kubernetes-security-specialist/) maps cleanly to production security work. The weights below are the current blueprint, and this table is the shortest path from “what do I study” to “what will I build.”

| Domain | Weight | What You Actually Do |
| --- | --- | --- |
| Cluster Setup | 15% | NetworkPolicies, Center for Internet Security (CIS) checks with [kube-bench](https://github.com/aquasecurity/kube-bench), Ingress with TLS, binary verification |
| Cluster Hardening | 15% | [RBAC least privilege](https://adamtheautomator.com/kubernetes-rbac/), service account defaults, API restriction, upgrades |
| System Hardening | 10% | Host OS footprint, AppArmor, seccomp, IAM limits |
| Minimize Microservice Vulnerabilities | 20% | Pod Security Standards, secrets encryption, sandbox runtimes, mutual TLS (mTLS) |
| Supply Chain Security | 20% | Image scanning with Trivy, minimal base images, signing, allowed registries |
| Monitoring, Logging, and Runtime Security | 20% | Falco rules, audit logging, container immutability |

Two design choices drive most tasks. Kubernetes allows all pod-to-pod traffic until you deny it, so a default-deny NetworkPolicy is the starting point. Pod Security Admission grades pods at admission time, so a namespace label decides whether a privileged container can exist at all.

The six domains map to a single attack surface that stretches from the build pipeline to the running pod, and the diagram below shows where each domain applies.

![CKS domain control points](https://adamtheautomator.com/wp-content/uploads/publisher/a0c54500119f97bc3a7601b8b9f9bbb02bd2e296565192a1bb014690fea3f5f2.jpg)

### A Default-Deny NetworkPolicy You Will Reuse

```yaml
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: default-deny-all
  namespace: payments
spec:
  podSelector: {}
  policyTypes:
  - Ingress
  - Egress
```

The empty `podSelector` matches every pod in `payments`, and listing both policy types blocks inbound and outbound traffic until you add a policy that allows it. Apply it, then confirm with `kubectl get networkpolicy -n payments`. DNS egress to port 53 stays broken until you allow it, which is the most common self-inflicted failure in this domain.

Once the domains are mapped, decide where you will practice.

## Hands-On Lab Setup for CKS Practice

Reading about AppArmor profiles does not build the speed the exam demands. The [official Killer.sh simulator](https://killer.sh/cks) ships with your exam registration: two sessions, 36 hours of access each, and 17 graded questions per session. Killer.sh scenarios run harder than the exam on purpose, so a strong score there is real buffer.

Free options cover the rest of the runway. [Killercoda](https://killercoda.com/cks) provisions single-topic browser labs in seconds and works well for drilling one weak area. The open-source [CK-X simulator](https://github.com/sailor-sh/CK-X) runs full-length timed exams on k3d (the k3s-in-Docker distribution) and grades them automatically, which makes it the best way to rehearse under a clock without paying per attempt.

### Build a Cluster You Are Allowed to Break

For the domains that touch control-plane files, build with [kubeadm](https://adamtheautomator.com/kubeadm/). Managed services and simplified distributions hide or restrict the paths the exam expects you to edit, especially `/etc/kubernetes/manifests/`.

```bash
sudo kubeadm init --kubernetes-version v1.35.0
mkdir -p "$HOME/.kube"
sudo cp -i /etc/kubernetes/admin.conf "$HOME/.kube/config"
sudo chown "$(id -u):$(id -g)" "$HOME/.kube/config"
kubectl get nodes
```

Run these on a throwaway virtual machine, and substitute the exact release your blueprint lists for `v1.35.0`. The `--kubernetes-version` flag pins the build so your lab matches the exam instead of drifting onto whatever the package manager installs. Keep a second node as well, because several hardening tasks distinguish control-plane from worker behavior and a single-node cluster cannot show you the difference.

The lab topology below shows the exam-style layout: a base node you SSH from into a small cluster.

![CKS practice lab topology](https://adamtheautomator.com/wp-content/uploads/publisher/64dc1ae453fa90d3d4740032a89fdefe2a77bb664c889fa79ccaa1cfbd7d8b6a.jpg)

* * *

_**Warning: _**`kubeadm init`**_ reformats the machine’s container runtime and writes a new control plane to disk. Run it on a disposable VM with snapshots, never on a machine you also use for anything else.**_

* * *

With a lab in place, the tools become the next bottleneck.

## The Security Tools You Have to Operate

The exam clusters ship the binaries already installed, so your practice time goes to fluency with each tool. The [Trivy documentation](https://aquasecurity.github.io/trivy/) and the [Falco documentation](https://falco.org/docs/) are reachable inside the exam, and both are worth a dry run on your own cluster first.

*   kube-bench: runs the CIS Kubernetes Benchmark checks against `etcd`, `kubelet`, and the control plane, then prints pass or fail per control.
    
*   Trivy: scans container images and filesystems for known CVEs with severity filters.
    
*   Falco: watches syscalls at runtime and fires rules when behavior matches a threat pattern.
    
*   apparmor\_parser: loads AppArmor profiles onto a node.
    
*   [Cosign](https://docs.sigstore.dev/cosign/signing/overview/): signs and verifies image signatures.
    
*   OPA Gatekeeper / Kyverno: enforce admission policies (allowed registries, resource limits, required labels) beyond the built-in Pod Security Admission profiles.
    

### Scan an Image and Act on the Result

```bash
trivy image --severity HIGH,CRITICAL nginx:1.27.3
```

The severity flag trims the report to the findings that matter for a task. If the output lists a critical CVE in a base layer, the fix is to move the workload to a patched image; a scanner exception hides the finding without closing it.

### Patch an Insecure Pod Spec

```yaml
securityContext:
  runAsNonRoot: true
  readOnlyRootFilesystem: true
  allowPrivilegeEscalation: false
  seccompProfile:
    type: RuntimeDefault
  capabilities:
    drop: ["ALL"]
```

Every field closes a specific escalation path. `runAsNonRoot` blocks a root container, `readOnlyRootFilesystem` stops an attacker from writing a payload, `allowPrivilegeEscalation: false` blocks setuid tricks, `RuntimeDefault` applies the container runtime’s seccomp profile, and dropping all capabilities removes the default set a compromised process can reach.

### Enforce the Baseline at the Namespace

```bash
kubectl label namespace payments \
  pod-security.kubernetes.io/enforce=restricted \
  pod-security.kubernetes.io/audit=restricted \
  pod-security.kubernetes.io/warn=restricted
```

The admission controller reads these labels and rejects or flags any pod that violates the profile. The `enforce` label blocks the pod, while `audit` and `warn` record and surface violations without stopping them, which matters when you roll a profile onto a namespace that already runs workloads.

* * *

_**Pro Tip: Label a namespace with _**`warn`**_ and _**`audit`**_ first, watch the violations for a release cycle, then turn _**`enforce`**_ on. Jumping straight to restricted rejects pods that were already running.**_

* * *

The tooling is in hand. Turn next to the schedule that puts it under a clock.

## A Five-Week CKS Study Plan

Five weeks works if you already hold the CKA. The plan front-loads the two 20% supply chain and runtime domains, because they overlap least with CKA study and depend most on tooling.

1.  Week 1: Cluster hardening. RBAC least privilege, `automountServiceAccountToken: false`, API access restriction, and a zero-downtime `kubeadm` upgrade.
    
2.  Week 2: Supply chain. Minimal base images, Trivy scans in a pipeline, allowed registries, and a full `cosign sign` and `cosign verify` cycle.
    
3.  Week 3: Runtime security. Falco rules, Kubernetes audit policies, and `readOnlyRootFilesystem` enforcement.
    
4.  Week 4: Microservice vulnerabilities. Pod Security Standards across namespaces, [secrets encryption](https://adamtheautomator.com/kubernetes-secrets/) at rest, and a sandbox runtime class.
    
5.  Week 5: Full timed simulations. Run Killer.sh and CK-X end to end, then re-drill every task you failed.
    

Reserve the final two days for weak spots only. New topics introduced in the last 48 hours rarely survive the time pressure, and the [CKS curriculum](https://k8s-school.fr/labs/en/certifications/cks_curriculum/index.html) is a useful checklist for filling gaps in that window.

## Exam-Day Strategy and Time Management

The clock is the hardest opponent. Budget about six minutes per task and move on when a task stalls, because partial credit beats a perfect answer you never reach. Speed comes from two habits: a shell alias and YAML scaffolding.

```bash
alias k=kubectl
export do="--dry-run=client -o yaml"
k run web --image=nginx $do > pod.yaml
```

The `--dry-run=client -o yaml` pattern writes a starting manifest you edit instead of typing from scratch, and it is the single highest-value command in the exam.

### Use the Documentation, Do Not Read It

You can reach [kubernetes.io/docs](https://kubernetes.io/docs/), the [Kubernetes GitHub](https://github.com/kubernetes/), the Trivy site, the Falco site, the AppArmor wiki, and the Cilium, Istio, and etcd docs from the exam browser. None of that helps if you open a doc to learn a concept you never practiced. Use the allowed pages to confirm a field name, a flag, or an exact annotation, then close the tab.

## Most-Failed Topics and How to Avoid Them

The failures cluster around a few recurring mistakes. NetworkPolicy tasks break when a candidate forgets egress DNS to port 53, and every pod in the namespace loses service discovery. AppArmor tasks break when the profile name in `localhostProfile` does not match the file loaded on the node. Image admission tasks break when the policy rejects the workload image and the candidate edits the policy instead of the image reference.

### The Scenario That Breaks a Running Workload

Applying a security control that stops a production-shaped workload is the trap. If a new `enforce` label rejects a Deployment, correct the pod spec instead of removing the profile. The flow below shows how the admission controller blocks a container and how the event log leads you back to the offending field.

![PSA blocks a privileged pod](https://adamtheautomator.com/wp-content/uploads/publisher/c2302fb9967aa242dc3afbca5159f36b9b592074151df919df227bcfe9648669.jpg)

Verify the result with the same checks a grader would run.

```bash
kubectl get events -n payments --field-selector reason=FailedCreate
kubectl auth can-i list pods -n payments \
  --as=system:serviceaccount:payments:reporting
```

The first command shows the admission controller’s rejection reason, and the second probes an RBAC change from the service account’s point of view. Both are read-only, so you can run them repeatedly while you iterate.

RBAC mistakes deserve their own rehearsal, because a leftover `cluster-admin` binding is easy to create and hard to spot. The [Kubernetes RBAC documentation](https://kubernetes.io/docs/reference/access-authn-authz/rbac/) is the reference to keep open when you audit bindings.

## CKS Certification Cost, Retakes, and Whether It Is Worth Renewing in 2026

The exam fee runs about $445 USD and includes one free retake within 12 months plus the Killer.sh simulator. The credential stays valid for two years, and the [Linux Foundation CKS certification page](https://training.linuxfoundation.org/certification/certified-kubernetes-security-specialist/) carries the current pricing and terms. The renewal math changed on June 18, 2026, when the CNCF extended its Certification Advancement and Recertification Experience (CARE) program so that a CKS pass renews the CKA.

The [CNCF CARE announcement](https://www.cncf.io/blog/2026/06/17/expanding-care-passing-cks-can-now-extend-your-cka-certification/) is the primary source, and the [Linux Foundation CARE program page](https://training.linuxfoundation.org/care-program/) lists the current rules. Under the policy, passing or recertifying the CKS automatically reinstates or extends your CKA, and the CKA expiration date moves to match the new CKS date. The reinstatement applies even if the CKA had already expired.

### The June 2026 Rule in One Line

Pass or renew the CKS on or after June 18, 2026, and your CKA expiration date resets to match. The extension does not apply retroactively to CKS passes earned before that date.

That single change carries the value. A CKS pass on or after June 18, 2026 renews the CKA, the CKA cascade renews the Kubernetes and Cloud Native Associate (KCNA), and the CKS itself renews the Kubernetes and Cloud Native Security Associate (KCSA). One exam keeps KCNA, KCSA, CKA, and CKS current at once, which is the strongest argument for renewing the CKS rather than letting it lapse and re-earning the stack later.

## Frequently Asked Questions

The questions below come up in every CKS cohort. Short answers, with the source to confirm each one.

### Is the CKS harder than the CKA?

Yes, by workload. The CKA tests cluster operations you repeat often. The CKS tests security controls you touch less and must recall under a two-hour clock. The CKS curriculum assumes CKA fluency and layers tooling on top.

### Can I pass without hands-on practice?

No. The exam grades the cluster state you produce, and the [official CKS exam-environment rules](https://docs.linuxfoundation.org/tc-docs/certification/important-instructions-cks) describe a terminal-only environment where you type the fix yourself.

### How long is the CKS valid?

Two years from the pass date. Recertify by exam after that, and the 2026 CARE rule means the renewal also refreshes your CKA.

### How many attempts do I get?

One retake is bundled with the exam fee inside a 12-month window. Confirm the current terms on your voucher before you schedule.

## Where to Start This Week

Three moves put you on the clock. Confirm your CKA status in the [Linux Foundation training portal](https://training.linuxfoundation.org/) today, so an eligibility surprise does not surface three weeks before exam day. Stand up a disposable kubeadm cluster and apply the default-deny NetworkPolicy above, then break DNS and fix it, because that recovery is a task you will meet in some form. Finally, activate one Killer.sh session only after you can run kube-bench, Trivy, and a Falco rule without a tutorial open, since the simulator measures speed as much as knowledge. Get those three done and the remaining work becomes scheduling.

Share this article

[Share on X](https://twitter.com/intent/tweet?url=https%3A%2F%2Fadamtheautomator.com%2Fcks-certification-study-guide%2F&text=CKS%20Exam%202026%3A%20Study%20Guide%2C%20Practice%20Labs%20and%20Five-Week%20Plan)[Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fadamtheautomator.com%2Fcks-certification-study-guide%2F)[Share on LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fadamtheautomator.com%2Fcks-certification-study-guide%2F)

## Related Posts

![](https://adamtheautomator.com/wp-content/uploads/2026/07/featured_image-1.png)

### [A Practical Guide to Kubernetes Security Management](/practical-guide-kubernetes-security-management/)

Manage Kubernetes security with RBAC, Pod Security, network policies, posture scanning, and runtime detection using Kubescape, Falco, and Defender.

![](https://adamtheautomator.com/wp-content/uploads/2022/02/How-to-Install-and-Configure-the-CSF-Firewall-for-Linux.jpg)

### [How to Install and Configure the CSF Firewall for Linux](/csf-firewall/)

Learn how to install and configure the CSF firewall for Linux and secure your server in this step-by-step tutorial!

![](https://adamtheautomator.com/wp-content/uploads/2022/01/Configuring-Suricata-as-an-Intrusion-Prevention-System-IPS.jpg)

### [Configuring Suricata as an Intrusion Prevention System (IPS)](/suricata/)

Learn how to configure Suricata IPS to detect and prevent suspicious activities on your network with this step-by-step tutorial!

## Categories

*   [IT Ops](/category/it-ops/)
*   [Cloud](/category/cloud/)
*   [DevOps](/category/devops/)
*   [Home Ops](/category/home-ops/)
*   [Information Security](/category/infosec/)
*   [Software Development](/category/software-development/)

## Site

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Copyright 2026© ATA Learning | [Privacy Policy](/privacy/)
