The Linux Foundation / CNCF exam preparation
Certified Kubernetes Security Specialist (CKS)
Follow a topic roadmap built from the published exam blueprint, with lessons, practice exercises in a real terminal and practice exams.
The hardest of the three and the only one with a gate in front of it: you must already hold a current CKA to sit it.
What you'll learn
Every objective CKS publishes, and what it asks you to be able to do. The percentage is how much of the exam each one is worth.
- Minimize Microservice Vulnerabilities (20% of the exam)Use appropriate pod security standards. Manage kubernetes secrets. Understand and implement isolation techniques (multi-tenancy, sandboxed containers, etc.). Implement Pod-to-Pod encryption (Cilium, Istio).
- Supply Chain Security (20% of the exam)Minimize base image footprint. Understand your supply chain (e.g. SBOM, CI/CD, artifact repositories). Secure your supply chain (permitted registries, sign and validate artifacts, etc.). Perform static analysis of user workloads and container images (e.g. Kubesec, KubeLinter).
- Monitoring, Logging and Runtime Security (20% of the exam)Use Kubernetes audit logs to monitor access. Ensure immutability of containers at runtime. Perform behavioral analytics to detect malicious activities. Detect threats within physical infrastructure, apps, networks, data, users and workloads. Investigate and identify phases of attack and bad actors within the environment.
- Cluster Setup (15% of the exam)Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi). Verify platform binaries before deploying. Use Network security policies to restrict cluster level access. Properly set up Ingress objects with TLS. Protect node metadata and endpoints.
- Cluster Hardening (15% of the exam)Restrict access to Kubernetes API. Use Role Based Access Controls to minimize exposure. Exercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created ones. Upgrade Kubernetes to avoid vulnerabilities.
- System Hardening (10% of the exam)Minimize host OS footprint (reduce attack surface). Using least-privilege identity and access management. Minimize external access to the network. Appropriately use kernel hardening tools such as AppArmor, seccomp.
Explore related topics
The exam at a glance
- Length
- 2 hours
- Cost
- $445
- Validity
- 2 years
- Style
- Hands-on
Online proctored, performance-based, solved entirely at a command line. Based on Kubernetes v1.34.
A current CKA certification is required before you can sit this exam.
What to expect on the day
Confirmed 1 October 2026
Current detail on the CKS exam, beyond what its published format covers.
- kubectl is already there as `k`, with Bash autocompletion configured, on every host a task sends you to. You do not set either up and you do not lose tab completion.
- Nested ssh does not work: `exit` back to the base system, whose hostname is `base`, before you start the next task. `sudo -i` gets you root on any host.
- Do not reboot the base node, whose hostname is `base`. Rebooting it does not restart the exam environment.
- Copy and paste inside the terminal is Ctrl+Shift+C and Ctrl+Shift+V. Everywhere else on the desktop it is Ctrl+C and Ctrl+V.
- Ctrl+W closes the browser tab instead of deleting a word, so the exam remaps it to Ctrl+Alt+W. The INSERT key is blocked outright: press `i` to get into vim's insert mode.
- The environment runs Kubernetes v1.35. The published CKS curriculum, which the domains below are drawn from, is v1.34.
Sitting the exam
The part nobody publishes in a syllabus. For CKS the logistics are study strategy: what you are allowed to read while the clock runs changes how you should practise, and what a second attempt costs changes when you should book.
Where you sit it
- Online proctored through PSI's Bridge platform. You sit it in a secure browser on your own machine and work inside a Linux remote desktop, so the cluster is never local.
- The base node has no tooling on it. The work happens over SSH to the hosts each task names, where kubectl (aliased to k), yq, curl, wget and man pages are already installed.
- One monitor. Dual monitors are not supported, virtual machines are not permitted, and no other application or browser window may be running.
- A private walled room with the door closed, a clear desk with nothing on or under it, and nobody else present. Audio, video and your screen are streamed to a proctor for the full two hours, and you have to stay in the camera frame throughout.
What you are asked
- 15 to 20 performance-based tasks in 2 hours, solved at a command line against a live cluster.
- That is roughly 6 to 8 minutes a task on average, against tasks that are harder than CKA's for the same clock.
What you can look at
- Everything CKA and CKAD allow: the Kubernetes documentation (kubernetes.io/docs), the Kubernetes blog (kubernetes.io/blog) and the Helm documentation (helm.sh/docs).
- Plus the tooling this exam is actually about: Falco (falco.org/docs), etcd (etcd.io/docs), the NGINX Ingress Controller configuration guide (kubernetes.github.io/ingress-nginx), Cilium (docs.cilium.io), Istio (istio.io/latest/docs) and bom (kubernetes-sigs.github.io/bom).
- Searching within kubernetes.io/docs is allowed, but you must not open a search result that leads off it.
- Documentation shipped on the exam machine under /usr/share, the distribution's own packages, and the task instructions in the terminal.
- The extra domains are the study list. If you have never opened the Falco or Cilium docs before exam day, finding anything in them under time pressure will cost you a task.
How it is marked
- 67% or above is a pass, a mark higher than CKA and CKAD ask for.
- A score report reaches you by email within 24 hours of finishing.
Identification and proctoring
- One valid, unexpired, original government-issued photo ID, physically in your hand. Photocopies, photos of a document and electronic copies are all refused.
- Accepted: an international travel passport, a government-issued driving licence or permit, a national identity card, a state or province identity card, an alien registration or permanent resident card, and in Japan the Basic Resident Register card or My Number card.
- It has to carry your name, photo and signature. A government-issued biometric ID with no signature is accepted.
- The first and last name on your Linux Foundation account must match the ID exactly. If the ID is in a non-Latin script, enter your name in that script rather than a transliteration.
- Check-in includes uploading a picture of the ID. Being assigned a check-in specialist should take no more than 15 minutes, so start early.
If you do not pass
- One retake is included in the exam price, granted when the first attempt is graded as not passed. It is not a second exam you buy.
- The retake has to be taken within 12 months of the original purchase, or before a corporate subscription expires, whichever comes first.
- Registrations sold as SINGLE or SINGLE-ATTEMPT get one attempt and no simulator. Check which one you are buying.
- Bought through an authorised training partner? Retake eligibility is the partner's to confirm, not the Linux Foundation's.
Booking it
- You must have taken and passed the CKA before you attempt this exam. It is the only one of the three with a gate in front of it.
- 12 months from purchase to schedule and sit it.
- $445 for the exam alone. Bundles with a subscription at $625 and with a course at $645 are also listed.
- You accept the Linux Foundation Global Certification and Confidentiality Agreement at registration and again before testing. Declining it ends the exam and the fee is not refunded.
What comes with it
- Two exam simulator attempts from Killer.sh, each giving 36 hours of access from the moment you activate it. Candidates routinely never claim these.
- The simulator's questions are the same for every attempt and every candidate, unlike the real exam. Treat it as a rehearsal of the environment and the clock, not a preview of the tasks.
Read off the official exam page on 25 August 2026. Rules change without notice, so confirm anything you are about to spend money on.
What the exam covers
Straight from the published curriculum. The weights are how much of the exam each area is worth, so they are the honest guide to where your study time should go.
Course content
27 topics
1. The Kubernetes Attack Surface
Where a Kubernetes cluster can be attacked: the control plane, the kubelet, the container runtime, the network and the supply chain, and which of them each later topic hardens.
2. Reviewing a Cluster Against the CIS Benchmark
- Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
3. Verifying Platform Binaries Before Deploying
- Verify platform binaries before deploying
4. Restricting Access to the Kubernetes API
- Restrict access to Kubernetes API
5. Using RBAC to Minimize Exposure
- Use Role Based Access Controls to minimize exposure
6. Service Accounts: Disabling Defaults and Minimizing Permissions
- Exercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created ones
7. Upgrading Kubernetes to Avoid Vulnerabilities
- Upgrade Kubernetes to avoid vulnerabilities
8. Restricting Cluster-Level Access with Network Policies
- Use Network security policies to restrict cluster level access
9. Setting Up Ingress Objects with TLS
- Properly set up Ingress objects with TLS
10. Protecting Node Metadata and Endpoints
- Protect node metadata and endpoints
11. Minimizing the Host OS Footprint
- Minimize host OS footprint (reduce attack surface)
12. Least-Privilege Identity and Access Management
- Using least-privilege identity and access management
13. Minimizing External Access to the Network
- Minimize external access to the network
14. Kernel Hardening with AppArmor and seccomp
- Appropriately use kernel hardening tools such as AppArmor, seccomp
15. Pod Security Standards
- Use appropriate pod security standards
16. Managing Kubernetes Secrets
- Manage kubernetes secrets
17. Isolation: Multi-Tenancy and Sandboxed Containers
- Understand and implement isolation techniques (multi-tenancy, sandboxed containers, etc.)
18. Pod-to-Pod Encryption with Cilium and Istio
- Implement Pod-to-Pod encryption (Cilium, Istio)
19. Minimizing the Base Image Footprint
- Minimize base image footprint
20. Knowing Your Supply Chain: SBOM, CI/CD and Artifact Repositories
- Understand your supply chain (e.g. SBOM, CI/CD, artifact repositories)
21. Securing the Supply Chain: Permitted Registries and Artifact Signing
- Secure your supply chain (permitted registries, sign and validate artifacts, etc.)
22. Static Analysis of Workloads and Images
- Perform static analysis of user workloads and container images (e.g. Kubesec, KubeLinter)
23. Monitoring Access with Kubernetes Audit Logs
- Use Kubernetes audit logs to monitor access
24. Ensuring Container Immutability at Runtime
- Ensure immutability of containers at runtime
25. Behavioral Analytics for Malicious Activity
- Perform behavioral analytics to detect malicious activities
26. Detecting Threats Across Infrastructure, Apps, Networks and Users
- Detect threats within physical infrastructure, apps, networks, data, users and workloads
27. Investigating the Phases of an Attack
- Investigate and identify phases of attack and bad actors within the environment
What to know before you start
- Everything CKA covers, at working speed
- Linux security primitives: users, capabilities, seccomp, AppArmor
- How an image gets from a registry into a running pod
Other The Linux Foundation / CNCF certifications
All The Linux Foundation / CNCF certificationsFrequently asked questions
How much does the CKS exam cost?
$445. Confirm it on The Linux Foundation / CNCF's page before you book: exam fees change.
How long is the CKS exam?
2 hours. Online proctored, performance-based, solved entirely at a command line.
How many questions are on the CKS exam?
15 to 20 performance-based tasks in 2 hours, solved at a command line against a live cluster. Check the current count with The Linux Foundation / CNCF before you book.
How long is CKS valid?
2 years. Check The Linux Foundation / CNCF's recertification route before it lapses.
Is the CKS exam hands-on?
Yes. It is performance-based: you are given a live environment and a command line, and marked on what you actually do rather than what you can recognise. Reading alone does not prepare you for it.
What is on the CKS exam?
6 domains. The heaviest is Minimize Microservice Vulnerabilities at 20% of the exam, so it is the one worth over-preparing.
What should I know before starting CKS?
Everything CKA covers, at working speed. Linux security primitives: users, capabilities, seccomp, AppArmor. How an image gets from a registry into a running pod.
CKS vs CKA: what is the difference?
CKS: 2 hours, $445, hands-on. CKA: 2 hours, $445, hands-on. Both are The Linux Foundation / CNCF exams with their own guide on this site.
Exam details from The Linux Foundation / CNCF, checked August 2026. Always confirm on their page before booking.
What learners say about Acelro
About Acelro rather than the CKS exam: what learners made of the gap analysis, the roadmap and the projects.
“The roadmap makes me focus on a learning curve, no matter the length.”
“Acelro has been really great for me, an inspiring experience. I've gained a lot of confidence doing projects I thought were rocket science.”
“The gap analysis maps your actual skills against what the current job market is asking for. Nobody else made it that clear where I stood.”