You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The Certified Kubernetes Security Specialist (CKS) certification validates advanced, hands-on skills in securing Kubernetes clusters and cloud-native workloads. Designed for experienced Kubernetes practitioners, it covers cluster hardening, supply chain security, and runtime threat detection. Earning CKS proves you can implement and maintain robust security controls in production environments, making you a valuable asset for security-focused DevOps and SRE roles.
Content last reviewed 30 July 2026 · Up to date
What this certification covers, who it is written for, and what the exam itself looks like on the day.
What it validates, who it is written for, and the experience it assumes.
Certified Kubernetes Security Specialist (CKS) is graded entirely on tasks you perform in a live environment, so there is no multiple-choice practice bank. To prepare: practice each objective hands-on in a real sandbox or lab; drill the key commands and workflows until they are second nature; work through timed task scenarios and verify your end state; and review the official documentation for every objective. The full objective breakdown is in the Curriculum tab.
The Certified Kubernetes Security Specialist (CKS) certification is a performance-based credential that validates your ability to secure Kubernetes clusters and containerized applications. Created by the Linux Foundation and the Cloud Native Computing Foundation (CNCF), this exam goes beyond theoretical knowledge, requiring you to solve real-world security challenges directly from the command line. It is designed for experienced Kubernetes administrators who want to demonstrate their expertise in cluster hardening, supply chain security, and runtime threat detection.
Earning the CKS certification proves you have the practical skills to implement robust security controls across the entire Kubernetes lifecycle. From configuring network policies and RBAC to securing the software supply chain and monitoring for malicious activity, you will be equipped to protect production environments against evolving threats. This globally recognized, vendor-neutral credential is a powerful differentiator for DevOps engineers, SREs, and cloud professionals seeking to advance their careers in cloud-native security.
The CKS certification is intended for experienced Kubernetes practitioners who are responsible for securing Kubernetes clusters and cloud-native applications. This includes DevOps engineers, site reliability engineers (SREs), system administrators, and cloud professionals who want to validate their advanced security skills. Candidates should already have a strong foundation in Kubernetes administration and be comfortable working from the command line. This certification is ideal for those who want to demonstrate their ability to implement and maintain security best practices in production environments. It is also valuable for professionals looking to specialize in cloud-native security, as it covers a broad range of topics from cluster hardening to runtime threat detection.
While not mandatory, the Linux Foundation recommends that candidates have a solid understanding of Kubernetes administration and security concepts. The exam is designed for intermediate-level professionals. Hands-on experience with Kubernetes cluster administration; Familiarity with Linux command-line tools and shell scripting; Understanding of Kubernetes security concepts such as RBAC, network policies, and pod security standards; Knowledge of container security best practices and supply chain security
Every domain and objective Linux Foundation measures, with the weight they carry on the exam.
The official Linux Foundation exam outline · checked 30 July 2026 · See the source
Everything Linux Foundation publishes about sitting it, and nothing we inferred.
Must have passed the Certified Kubernetes Administrator (CKA) exam
The path Linux Foundation lays out, how the credential is kept, and where to book.
Step-by-step path to Certified Kubernetes Security Specialist (CKS)
The CKS certification is valid for two years. To renew, you must pass the current CKS exam again before the expiration date. Stay current with the latest technologies and maintain your certification.
Learn more about renewal requirementsThis certification is currently active and available. Linux Foundation maintains this certification to validate current skills and industry relevance.
Register for the exam through Linux Foundation, Linux Foundation’s authorized testing partner.
Schedule your examVisit the official Linux Foundation certification page for exam policies and requirements.
View the official pageYour coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.
See how the coach worksThe CKS exam is a higher-level security certification that requires you to have already passed the CKA exam. It builds on the CKA's Kubernetes administration skills and focuses specifically on security.
Yes, the CKS exam is a performance-based test that requires you to solve multiple tasks from a command line running Kubernetes. It is not a multiple-choice exam.
The CKS exam includes two exam attempts. If you fail the first attempt, you can retake it. The specific waiting period between attempts is not published on the official page.
Yes, once enrolled, you receive access to an exam simulator provided by Killer.sh. You get two simulation attempts, each with 36 hours of access, and each session includes 17 questions with graded results.
The CKS certification is best suited for advanced professionals working as DevOps, SRE, SysAdmin, and Cloud Professionals who want to demonstrate their Kubernetes security skills.
No, the CKS certification must be renewed by passing the current CKS exam again. There is no alternative exam for renewal.
The exam interface is available in English and Japanese, as indicated on the official Japanese page.
Every domain, every objective, and every concept Linux Foundation measures — each one written out.





Every objective below is a page you can open and practise now, without an account.
The official Linux Foundation exam outline · checked 30 July 2026 · See the source
In front of every objective the practice pages are already there, free and without an account. This is one objective, opened.
25 questions on this objective, five to a page. Every range above is a real page, open now, with no account.
The curriculum tells you what is on the exam. Proving you know it is a different job — and it is the one the closed-book run does.
The whole bank is open. 5 questions to a page, every answer explained, and a discussion thread on each one.
Every objective, and every page range, is a link — so you can pick up exactly where you left off.
Short enough to finish, long enough to matter.
Not only which one is right — why the others are wrong.
Ask, answer, and vote. Every question has its own thread.
These are not trivia. Each one is written against a concept in the book, so when you get one wrong there is somewhere to go and find out why.

The pages shown here come from our AI-900 book — an example of how each concept is written in plain language and, where the idea needs one, drawn as a full page you can take in at a glance.





Three reasons, and each one is a real finding rather than a slogan.
You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The whole idea at onceWhere it starts, what happens in the middle, what comes out, and the mistake to avoid.
Multimedia principle · Mayer
The look-alikes sit togetherThe pairs the exam tests are drawn side by side, so the difference is seen, not told.
Dual coding · PaivioYou are never asked to read a poster here — only to see how one is built. After that, every other page is legible at a glance.

The idea as a sequence, followed with a finger before a word is read.
What it is, how the machine learns it, when it is the right tool.
The distinction the exam tests, given its own box instead of buried in prose.
The sentence to carry into the exam room.
This is the part that teaches. The illustration and the written explanation stay where they are while you work, so a scenario stops being a memory test and becomes something you can simply look at.
A smartphone uses AI to unlock when the owner looks at the camera. Which AI capability is being used?

The same questions come back with the book closed — that run is the one that counts. After it, your coach picks one thing for tonight, sized to the time you have, and brings pages back before you lose them.
Testing effect · Roediger & Karpicke 2006 · spacing effect · Cepeda et al. 2006
Where the exam is defined, scheduled and scored.
We link to them rather than repeat them, so nothing here goes stale behind them.
We build from the official skills outline, not from a summary of it — 26 objectives, 179 concepts written under them, and free questions against every one. When Linux Foundation changes the outline, this page changes with it.
That is the only question worth answering the night before, and no link answers it. You answer it by taking the questions with the book closed, and seeing what comes back.