You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The Kubernetes and Cloud Native Security Associate (KCSA) certification validates your foundational knowledge of security in the cloud native ecosystem. Designed for beginners, it covers everything from the 4Cs of cloud native security to Kubernetes cluster component security, threat modeling, and compliance frameworks. Earning the KCSA is the perfect first step toward a career in cloud security, demonstrating your readiness to advance to professional-level certifications.
Content last reviewed 30 July 2026 · Up to date
What this certification covers, who it is written for, and what the exam itself looks like on the day.
What it validates, who it is written for, and the experience it assumes.
The Kubernetes and Cloud Native Security Associate (KCSA) is a pre-professional certification designed for candidates interested in advancing to the professional level through a demonstrated understanding of foundational knowledge and skills of security technologies in the cloud native ecosystem. It is an entry-level credential that proves you have the baseline security knowledge needed to secure Kubernetes clusters and cloud native applications.
The exam covers a broad range of topics, including the 4Cs of cloud native security, Kubernetes cluster component security, Kubernetes security fundamentals, threat modeling, platform security, and compliance frameworks. By earning the KCSA, you demonstrate to employers that you understand the core security concepts and best practices essential for protecting modern cloud native environments. This certification is vendor-neutral, offering career flexibility and industry-wide recognition.
The KCSA is ideal for individuals who are new to cloud security and want to start their career in this field. It is designed for candidates with little to no experience, providing a solid foundation in cloud native security concepts. Whether you are a student, a developer, or an IT professional looking to pivot into security, the KCSA offers a clear path to building your expertise. This certification is also valuable for those who work with Kubernetes and cloud native technologies and want to deepen their understanding of security. It is a great starting point before pursuing more advanced certifications like the Certified Kubernetes Security Specialist (CKS).
While there are no mandatory prerequisites, the Linux Foundation recommends that candidates have some familiarity with Kubernetes and cloud native concepts. The free Introduction to Kubernetes course and the Kubernetes & Cloud Native Essentials course are excellent resources to build foundational knowledge before attempting the exam. Basic understanding of Kubernetes architecture and components; Familiarity with cloud native ecosystem and containerization; Awareness of fundamental security concepts (e.g., authentication, authorization, network policies)
Every domain and objective Linux Foundation measures, with the weight they carry on the exam.
The official Linux Foundation exam outline · checked 30 July 2026 · See the source
Everything Linux Foundation publishes about sitting it, and nothing we inferred.
No mandatory prerequisites — this certification has no required predecessor exam or credential.
The path Linux Foundation lays out, how the credential is kept, and where to book.
Step-by-step path to Kubernetes and Cloud Native Security Associate (KCSA)
The KCSA certification is valid for 2 years. To maintain the credential, you must renew before it expires. The renewal process typically involves retaking the exam or completing continuing education activities as specified by the Linux Foundation. Stay current with the latest technologies and maintain your certification.
Learn more about renewal requirementsThis certification is currently active and available. Linux Foundation maintains this certification to validate current skills and industry relevance.
Register for the exam through Linux Foundation, Linux Foundation’s authorized testing partner.
Schedule your examVisit the official Linux Foundation certification page for exam policies and requirements.
View the official pageYour coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.
See how the coach worksThe KCSA is a pre-professional certification that serves as a stepping stone to the CKS. While the CKS requires the CKA credential and focuses on advanced security skills, the KCSA provides the foundational security knowledge needed to pursue the CKS. Many candidates take the KCSA before attempting the CKS.
No, there are no prerequisites for the KCSA exam. You can take it directly, even if you have no prior certifications.
Yes, the KCSA exam is delivered online and is proctored. You can take it from your own location, provided you meet the technical and environmental requirements.
The KCSA exam includes two exam attempts. If you fail the first attempt, you can retake the exam once. The specific waiting period between attempts is outlined in the Candidate Handbook.
No, the KCSA exam is a multiple-choice exam. It does not include hands-on labs or performance-based tasks.
The KCSA is designed for individuals pursuing careers in cloud security, including roles such as security analyst, cloud security associate, and Kubernetes security specialist. It is also beneficial for developers and operations professionals who want to enhance their security knowledge.
The KCSA certification is valid for 2 years. To renew, you may need to retake the KCSA exam or complete approved continuing education. Passing a higher-level certification like the CKA or CKS may also count toward renewal, but you should check the latest renewal policy.
The KCSA exam is currently offered in English. The Linux Foundation may add other languages in the future, but no other languages are officially listed at this time.
Every domain, every objective, and every concept Linux Foundation measures — each one written out.





Every objective below is a page you can open and practise now, without an account.
The official Linux Foundation exam outline · checked 30 July 2026 · See the source
In front of every objective the practice pages are already there, free and without an account. This is one objective, opened.
18 questions on this objective, five to a page. Every range above is a real page, open now, with no account.
The curriculum tells you what is on the exam. Proving you know it is a different job — and it is the one the closed-book run does.
The whole bank is open. 5 questions to a page, every answer explained, and a discussion thread on each one.
Every objective, and every page range, is a link — so you can pick up exactly where you left off.
Short enough to finish, long enough to matter.
Not only which one is right — why the others are wrong.
Ask, answer, and vote. Every question has its own thread.
These are not trivia. Each one is written against a concept in the book, so when you get one wrong there is somewhere to go and find out why.

The pages shown here come from our AI-900 book — an example of how each concept is written in plain language and, where the idea needs one, drawn as a full page you can take in at a glance.





Three reasons, and each one is a real finding rather than a slogan.
You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The whole idea at onceWhere it starts, what happens in the middle, what comes out, and the mistake to avoid.
Multimedia principle · Mayer
The look-alikes sit togetherThe pairs the exam tests are drawn side by side, so the difference is seen, not told.
Dual coding · PaivioYou are never asked to read a poster here — only to see how one is built. After that, every other page is legible at a glance.

The idea as a sequence, followed with a finger before a word is read.
What it is, how the machine learns it, when it is the right tool.
The distinction the exam tests, given its own box instead of buried in prose.
The sentence to carry into the exam room.
This is the part that teaches. The illustration and the written explanation stay where they are while you work, so a scenario stops being a memory test and becomes something you can simply look at.
A smartphone uses AI to unlock when the owner looks at the camera. Which AI capability is being used?

The same questions come back with the book closed — that run is the one that counts. After it, your coach picks one thing for tonight, sized to the time you have, and brings pages back before you lose them.
Testing effect · Roediger & Karpicke 2006 · spacing effect · Cepeda et al. 2006
Where the exam is defined, scheduled and scored.
We link to them rather than repeat them, so nothing here goes stale behind them.
We build from the official skills outline, not from a summary of it — 34 objectives, 214 concepts written under them, and free questions against every one. When Linux Foundation changes the outline, this page changes with it.
That is the only question worth answering the night before, and no link answers it. You answer it by taking the questions with the book closed, and seeing what comes back.