Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
LINUX FOUNDATION

Certified Kubernetes Security Specialist (CKS)

CKSCertified Kubernetes Security Specialist

The Certified Kubernetes Security Specialist (CKS) certification validates advanced, hands-on skills in securing Kubernetes clusters and cloud-native workloads. Designed for experienced Kubernetes practitioners, it covers cluster hardening, supply chain security, and runtime threat detection. Earning CKS proves you can implement and maintain robust security controls in production environments, making you a valuable asset for security-focused DevOps and SRE roles.

566 practice questions · Updated 2026-07-30

6Domains
26Objectives
179Concepts
566Questions

CKS Curriculum

Every domain, objective, and concept the CKS exam measures.

Secure Cluster Components

7 concepts · 25 questions
  1. CIS Benchmark Overview
  2. Reviewing etcd Security
  3. Reviewing kubelet Security
  4. Reviewing kube-apiserver Security
  5. Reviewing kube-dns/CoreDNS Security
  6. Verifying Platform Binaries
  7. Upgrading Kubernetes

Network Security

11 concepts · 20 questions
  1. NetworkPolicy fundamentals
  2. Default deny and allow rules
  3. NetworkPolicy namespace isolation
  4. Ingress TLS termination
  5. Ingress TLS secrets management
  6. Ingress annotations and TLS options
  7. Node metadata protection
  8. Kubernetes API endpoint protection
  9. Pod-to-pod encryption with Cilium
  10. Pod-to-pod encryption with Istio
  11. mTLS policy enforcement

Access Control

10 concepts · 21 questions
  1. RBAC Role and RoleBinding
  2. RBAC ClusterRole and ClusterRoleBinding
  3. RBAC Principle of Least Privilege
  4. Service Account Defaults
  5. Service Account Permissions
  6. Service Account Token Management
  7. API Server Authentication Methods
  8. API Server Authorization Modes
  9. API Server Network Restrictions
  10. Kubeconfig and Context Security

Workload and Data Security

11 concepts · 28 questions
  1. Pod Security Standards
  2. Pod Security Admission
  3. Pod Security Contexts
  4. Secrets Management
  5. Secret Encryption at Rest
  6. Secret Security Best Practices
  7. Namespace-Based Isolation
  8. Network Policies for Isolation
  9. Sandboxed Containers
  10. RuntimeClass for Isolation
  11. Multi-Tenancy Strategies

Minimize base image footprint

8 concepts · 27 questions
  1. Base image selection
  2. Image size reduction techniques
  3. Scanning for vulnerabilities
  4. Using minimal runtime dependencies
  5. Avoiding unnecessary layers
  6. Leveraging distroless images
  7. Pinning base image versions
  8. Regularly updating base images
  1. SBOM basics
  2. SBOM generation and formats
  3. SBOM verification and use
  4. CI/CD pipeline security
  5. Artifact repository security
  6. Supply chain attack vectors
  7. Trust and provenance
  1. Permitted Registries
  2. Image Signing and Verification
  3. Image Vulnerability Scanning
  4. Supply Chain Security Policies
  1. Static analysis fundamentals
  2. Kubesec usage
  3. KubeLinter usage
  4. Analyzing container images
  5. Integrating static analysis into CI/CD
  6. Interpreting and remediating findings

  1. Understand host OS footprint
  2. Identify unnecessary components
  3. Apply minimal base images
  4. Harden host OS configuration
  5. Use immutable infrastructure
  6. Monitor and audit host changes
  1. RBAC Role and RoleBinding
  2. ClusterRole and ClusterRoleBinding
  3. ServiceAccount creation and configuration
  4. Binding ServiceAccounts to Roles
  5. Least-privilege permission assignment
  6. Default ServiceAccount restriction
  7. RBAC verification and testing

Minimize external access to the network

9 concepts · 15 questions
  1. Network Policies
  2. Default Deny Ingress
  3. Default Deny Egress
  4. Allow Specific Ingress Rules
  5. Allow Specific Egress Rules
  6. Namespace Isolation
  7. Pod-to-Pod Communication Control
  8. External Traffic Restriction
  9. NetworkPolicy Testing and Validation
  1. AppArmor fundamentals
  2. AppArmor profiles
  3. Applying AppArmor in Kubernetes
  4. seccomp fundamentals
  5. seccomp profiles
  6. Applying seccomp in Kubernetes
  7. Troubleshooting kernel hardening

  1. Behavioral Analytics Fundamentals
  2. Kubernetes Audit Logs
  3. Audit Log Analysis
  4. Runtime Security Monitoring
  5. Threat Detection Techniques
  6. Incident Response and Remediation
  1. Threat detection fundamentals
  2. Physical infrastructure threat detection
  3. Application threat detection
  4. Network threat detection
  5. Data threat detection
  6. User threat detection
  7. Workload threat detection
  1. Attack phases in Kubernetes
  2. Kubernetes threat actors
  3. Attack surface mapping
  4. Indicators of compromise (IoCs)
  5. Forensic investigation techniques
  1. Immutable container filesystems
  2. Read-only root filesystem enforcement
  3. Ephemeral storage for writable layers
  4. Runtime security policies for immutability
  5. Verifying container immutability
  1. Audit logging fundamentals
  2. Audit policy configuration
  3. Audit log backend setup
  4. Audit log analysis
  5. Monitoring access patterns

  1. Understand host OS footprint
  2. Identify unnecessary services and packages
  3. Disable and remove unnecessary services
  4. Apply security updates and patches
  5. Harden kernel parameters
  6. Use minimal base images
  7. Restrict host access
  1. Principle of Least Privilege
  2. Kubernetes RBAC Authorization
  3. Service Account Management
  4. Role and ClusterRole Definitions
  5. RoleBinding and ClusterRoleBinding
  6. Least-Privilege Namespace Design
  7. Auditing and Monitoring Access
  8. Avoiding Privilege Escalation

Minimize external access to the network

6 concepts · 10 questions
  1. NetworkPolicy
  2. Default Deny
  3. Namespace Isolation
  4. External Traffic Control
  5. Ingress and Egress Rules
  6. Policy Testing
  1. AppArmor profiles
  2. Loading AppArmor profiles
  3. Applying AppArmor in Kubernetes
  4. seccomp profiles
  5. Applying seccomp in Kubernetes
  6. Default seccomp profiles
  7. Troubleshooting kernel hardening

  1. Falco rule syntax
  2. Falco event sources
  3. Detecting malicious container activity
  4. Kubernetes audit log analysis
  5. Behavioral analytics with Falco
  6. Falco configuration and deployment
  7. Responding to detected threats
  1. Threat Detection Fundamentals
  2. Physical Infrastructure Monitoring
  3. Application Threat Detection
  4. Network Threat Detection
  5. Data Threat Detection
  6. User and Identity Threat Detection
  7. Workload Threat Detection
  1. Phases of Attack
  2. Bad Actor Identification
  3. Attack Indicators
  4. Investigation Techniques
  5. Environment Context
  1. Container Immutability Principle
  2. Read-Only Root Filesystem
  3. EmptyDir for Writable Areas
  4. Security Contexts for Immutability
  5. Verifying Runtime Immutability
  1. Audit logging architecture
  2. Audit policy configuration
  3. Audit log backends
  4. Enabling audit logging
  5. Interpreting audit events
  6. Monitoring access with audit logs
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CKS, so none is invented.