Skip to main content

The Linux Foundation / CNCF exam preparation

Certified Kubernetes Security Specialist (CKS)

Follow a topic roadmap built from the published exam blueprint, with lessons, practice exercises in a real terminal and practice exams.

The hardest of the three and the only one with a gate in front of it: you must already hold a current CKA to sit it.

Lessons, quizzes and hands-on practice across every CKS objective, added to your roadmap. Free account.
Not ready to start? Tell us you want it and nothing else changes.

What you'll learn

Every objective CKS publishes, and what it asks you to be able to do. The percentage is how much of the exam each one is worth.

  • Minimize Microservice Vulnerabilities (20% of the exam)Use appropriate pod security standards. Manage kubernetes secrets. Understand and implement isolation techniques (multi-tenancy, sandboxed containers, etc.). Implement Pod-to-Pod encryption (Cilium, Istio).
  • Supply Chain Security (20% of the exam)Minimize base image footprint. Understand your supply chain (e.g. SBOM, CI/CD, artifact repositories). Secure your supply chain (permitted registries, sign and validate artifacts, etc.). Perform static analysis of user workloads and container images (e.g. Kubesec, KubeLinter).
  • Monitoring, Logging and Runtime Security (20% of the exam)Use Kubernetes audit logs to monitor access. Ensure immutability of containers at runtime. Perform behavioral analytics to detect malicious activities. Detect threats within physical infrastructure, apps, networks, data, users and workloads. Investigate and identify phases of attack and bad actors within the environment.
  • Cluster Setup (15% of the exam)Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi). Verify platform binaries before deploying. Use Network security policies to restrict cluster level access. Properly set up Ingress objects with TLS. Protect node metadata and endpoints.
  • Cluster Hardening (15% of the exam)Restrict access to Kubernetes API. Use Role Based Access Controls to minimize exposure. Exercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created ones. Upgrade Kubernetes to avoid vulnerabilities.
  • System Hardening (10% of the exam)Minimize host OS footprint (reduce attack surface). Using least-privilege identity and access management. Minimize external access to the network. Appropriately use kernel hardening tools such as AppArmor, seccomp.

Explore related topics

The exam at a glance

Length
2 hours
Cost
$445
Validity
2 years
Style
Hands-on

Online proctored, performance-based, solved entirely at a command line. Based on Kubernetes v1.34.

A current CKA certification is required before you can sit this exam.

What to expect on the day

Confirmed 1 October 2026

Current detail on the CKS exam, beyond what its published format covers.

  • kubectl is already there as `k`, with Bash autocompletion configured, on every host a task sends you to. You do not set either up and you do not lose tab completion.
  • Nested ssh does not work: `exit` back to the base system, whose hostname is `base`, before you start the next task. `sudo -i` gets you root on any host.
  • Do not reboot the base node, whose hostname is `base`. Rebooting it does not restart the exam environment.
  • Copy and paste inside the terminal is Ctrl+Shift+C and Ctrl+Shift+V. Everywhere else on the desktop it is Ctrl+C and Ctrl+V.
  • Ctrl+W closes the browser tab instead of deleting a word, so the exam remaps it to Ctrl+Alt+W. The INSERT key is blocked outright: press `i` to get into vim's insert mode.
  • The environment runs Kubernetes v1.35. The published CKS curriculum, which the domains below are drawn from, is v1.34.

Sitting the exam

The part nobody publishes in a syllabus. For CKS the logistics are study strategy: what you are allowed to read while the clock runs changes how you should practise, and what a second attempt costs changes when you should book.

Where you sit it

  • Online proctored through PSI's Bridge platform. You sit it in a secure browser on your own machine and work inside a Linux remote desktop, so the cluster is never local.
  • The base node has no tooling on it. The work happens over SSH to the hosts each task names, where kubectl (aliased to k), yq, curl, wget and man pages are already installed.
  • One monitor. Dual monitors are not supported, virtual machines are not permitted, and no other application or browser window may be running.
  • A private walled room with the door closed, a clear desk with nothing on or under it, and nobody else present. Audio, video and your screen are streamed to a proctor for the full two hours, and you have to stay in the camera frame throughout.

What you are asked

  • 15 to 20 performance-based tasks in 2 hours, solved at a command line against a live cluster.
  • That is roughly 6 to 8 minutes a task on average, against tasks that are harder than CKA's for the same clock.

What you can look at

  • Everything CKA and CKAD allow: the Kubernetes documentation (kubernetes.io/docs), the Kubernetes blog (kubernetes.io/blog) and the Helm documentation (helm.sh/docs).
  • Plus the tooling this exam is actually about: Falco (falco.org/docs), etcd (etcd.io/docs), the NGINX Ingress Controller configuration guide (kubernetes.github.io/ingress-nginx), Cilium (docs.cilium.io), Istio (istio.io/latest/docs) and bom (kubernetes-sigs.github.io/bom).
  • Searching within kubernetes.io/docs is allowed, but you must not open a search result that leads off it.
  • Documentation shipped on the exam machine under /usr/share, the distribution's own packages, and the task instructions in the terminal.
  • The extra domains are the study list. If you have never opened the Falco or Cilium docs before exam day, finding anything in them under time pressure will cost you a task.

How it is marked

  • 67% or above is a pass, a mark higher than CKA and CKAD ask for.
  • A score report reaches you by email within 24 hours of finishing.

Identification and proctoring

  • One valid, unexpired, original government-issued photo ID, physically in your hand. Photocopies, photos of a document and electronic copies are all refused.
  • Accepted: an international travel passport, a government-issued driving licence or permit, a national identity card, a state or province identity card, an alien registration or permanent resident card, and in Japan the Basic Resident Register card or My Number card.
  • It has to carry your name, photo and signature. A government-issued biometric ID with no signature is accepted.
  • The first and last name on your Linux Foundation account must match the ID exactly. If the ID is in a non-Latin script, enter your name in that script rather than a transliteration.
  • Check-in includes uploading a picture of the ID. Being assigned a check-in specialist should take no more than 15 minutes, so start early.

If you do not pass

  • One retake is included in the exam price, granted when the first attempt is graded as not passed. It is not a second exam you buy.
  • The retake has to be taken within 12 months of the original purchase, or before a corporate subscription expires, whichever comes first.
  • Registrations sold as SINGLE or SINGLE-ATTEMPT get one attempt and no simulator. Check which one you are buying.
  • Bought through an authorised training partner? Retake eligibility is the partner's to confirm, not the Linux Foundation's.

Booking it

  • You must have taken and passed the CKA before you attempt this exam. It is the only one of the three with a gate in front of it.
  • 12 months from purchase to schedule and sit it.
  • $445 for the exam alone. Bundles with a subscription at $625 and with a course at $645 are also listed.
  • You accept the Linux Foundation Global Certification and Confidentiality Agreement at registration and again before testing. Declining it ends the exam and the fee is not refunded.

What comes with it

  • Two exam simulator attempts from Killer.sh, each giving 36 hours of access from the moment you activate it. Candidates routinely never claim these.
  • The simulator's questions are the same for every attempt and every candidate, unlike the real exam. Treat it as a rehearsal of the environment and the clock, not a preview of the tasks.

Read off the official exam page on 25 August 2026. Rules change without notice, so confirm anything you are about to spend money on.

What the exam covers

Straight from the published curriculum. The weights are how much of the exam each area is worth, so they are the honest guide to where your study time should go.

Minimize Microservice Vulnerabilities20%
Supply Chain Security20%
Monitoring, Logging and Runtime Security20%
Cluster Setup15%
Cluster Hardening15%
System Hardening10%

Course content

27 topics

Where a Kubernetes cluster can be attacked: the control plane, the kubelet, the container runtime, the network and the supply chain, and which of them each later topic hardens.

  • Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
  • Verify platform binaries before deploying
  • Restrict access to Kubernetes API
  • Use Role Based Access Controls to minimize exposure
  • Exercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created ones
  • Upgrade Kubernetes to avoid vulnerabilities
  • Use Network security policies to restrict cluster level access
  • Properly set up Ingress objects with TLS
  • Protect node metadata and endpoints
  • Minimize host OS footprint (reduce attack surface)
  • Using least-privilege identity and access management
  • Minimize external access to the network
  • Appropriately use kernel hardening tools such as AppArmor, seccomp
  • Use appropriate pod security standards
  • Manage kubernetes secrets
  • Understand and implement isolation techniques (multi-tenancy, sandboxed containers, etc.)
  • Implement Pod-to-Pod encryption (Cilium, Istio)
  • Minimize base image footprint
  • Understand your supply chain (e.g. SBOM, CI/CD, artifact repositories)
  • Secure your supply chain (permitted registries, sign and validate artifacts, etc.)
  • Perform static analysis of user workloads and container images (e.g. Kubesec, KubeLinter)
  • Use Kubernetes audit logs to monitor access
  • Ensure immutability of containers at runtime
  • Perform behavioral analytics to detect malicious activities
  • Detect threats within physical infrastructure, apps, networks, data, users and workloads
  • Investigate and identify phases of attack and bad actors within the environment

What to know before you start

  • Everything CKA covers, at working speed
  • Linux security primitives: users, capabilities, seccomp, AppArmor
  • How an image gets from a registry into a running pod

Other The Linux Foundation / CNCF certifications

All The Linux Foundation / CNCF certifications

Frequently asked questions

How much does the CKS exam cost?

$445. Confirm it on The Linux Foundation / CNCF's page before you book: exam fees change.

How long is the CKS exam?

2 hours. Online proctored, performance-based, solved entirely at a command line.

How many questions are on the CKS exam?

15 to 20 performance-based tasks in 2 hours, solved at a command line against a live cluster. Check the current count with The Linux Foundation / CNCF before you book.

How long is CKS valid?

2 years. Check The Linux Foundation / CNCF's recertification route before it lapses.

Is the CKS exam hands-on?

Yes. It is performance-based: you are given a live environment and a command line, and marked on what you actually do rather than what you can recognise. Reading alone does not prepare you for it.

What is on the CKS exam?

6 domains. The heaviest is Minimize Microservice Vulnerabilities at 20% of the exam, so it is the one worth over-preparing.

What should I know before starting CKS?

Everything CKA covers, at working speed. Linux security primitives: users, capabilities, seccomp, AppArmor. How an image gets from a registry into a running pod.

CKS vs CKA: what is the difference?

CKS: 2 hours, $445, hands-on. CKA: 2 hours, $445, hands-on. Both are The Linux Foundation / CNCF exams with their own guide on this site.

Exam details from The Linux Foundation / CNCF, checked August 2026. Always confirm on their page before booking.

What learners say about Acelro

About Acelro rather than the CKS exam: what learners made of the gap analysis, the roadmap and the projects.

“The roadmap makes me focus on a learning curve, no matter the length.”
Daniel O., Career path navigation
“Acelro has been really great for me, an inspiring experience. I've gained a lot of confidence doing projects I thought were rocket science.”
Stephanie E., Learner
“The gap analysis maps your actual skills against what the current job market is asking for. Nobody else made it that clear where I stood.”
Cebuka B., Career changer

Not sure you are ready for CKS yet? Check where your skills stand in under a minute, no sign-up required.